First published: Fri Jan 17 2003(Updated: )
dhcpcd DHCP client daemon 1.3.22 and earlier allows local users to execute arbitrary code via shell metacharacters that are fed from a dhcpd .info script into a .exe script.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
dhcpcd | =1.3.17_pl2 | |
dhcpcd | =1.3.22_pl1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1403 is rated as a high severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2002-1403, upgrade to dhcpcd version 1.3.22_pl2 or later.
CVE-2002-1403 affects local users running dhcpcd versions 1.3.17_pl2 and 1.3.22_pl1.
CVE-2002-1403 enables local users to execute arbitrary code on the vulnerable system.
Yes, CVE-2002-1403 is specifically related to the dhcpcd DHCP client daemon's handling of scripts.