Release date:
Updated on:
Affected Systems:
BusyBox 1.18.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 48879
BusyBox is an executable implementation of many standard Linux tools.
BusyBox has a remote code execution vulnerability when escaping some shell metacharacters responded by the DHCP server. Remote attackers can exploit this vulnerability to forge a DHCP server and execute arbitrary commands with the superuser privilege.
Some shell metacharacters are not properly stripped or escaped during response from the DHCP server.
<* Source: vendor
Link: http://secunia.com/advisories/45363/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
BusyBox
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.busybox.net/