First published: Tue Jul 03 2012(Updated: )
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
T-mobile Tm-ac1900 | =3.0.0.4.376_3169 | |
Busybox Busybox | =1.11.0 | |
Busybox Busybox | =1.12.0 | |
Busybox Busybox | =1.0.0-pre7 | |
Busybox Busybox | =1.17.1 | |
Busybox Busybox | =1.7.0 | |
Busybox Busybox | =1.12.2 | |
Busybox Busybox | =1.1.3 | |
Busybox Busybox | =1.7.1 | |
Busybox Busybox | =1.0.0-pre3 | |
Busybox Busybox | =1.4.1 | |
Busybox Busybox | =1.11.3 | |
Busybox Busybox | =1.9.2 | |
Busybox Busybox | =1.1.0 | |
Busybox Busybox | =1.0.0-pre1 | |
Busybox Busybox | =1.13.4 | |
Busybox Busybox | =1.8.2 | |
Busybox Busybox | =1.10.0 | |
Busybox Busybox | =0.60.5 | |
Busybox Busybox | =1.17.0 | |
Busybox Busybox | =1.0.0-rc3 | |
Busybox Busybox | =1.19.2 | |
Busybox Busybox | =1.16.2 | |
Busybox Busybox | =1.9.1 | |
Busybox Busybox | =1.18.5 | |
Busybox Busybox | =1.18.4 | |
Busybox Busybox | =1.8.1 | |
Busybox Busybox | =1.2.1 | |
Busybox Busybox | =1.19.0 | |
Busybox Busybox | =1.0.0-pre4 | |
Busybox Busybox | =1.1.0-pre1 | |
Busybox Busybox | =1.14.2 | |
Busybox Busybox | =1.13.0 | |
Busybox Busybox | =1.5.0 | |
Busybox Busybox | =1.13.2 | |
Busybox Busybox | =1.10.2 | |
Busybox Busybox | =1.11.1 | |
Busybox Busybox | =1.17.2 | |
Busybox Busybox | =1.2.0 | |
Busybox Busybox | =1.3.2 | |
Busybox Busybox | =1.10.4 | |
Busybox Busybox | =1.01 | |
Busybox Busybox | =1.14.1 | |
Busybox Busybox | =1.0.0-pre2 | |
Busybox Busybox | =1.7.2 | |
Busybox Busybox | =1.0.0-rc2 | |
Busybox Busybox | =1.18.1 | |
Busybox Busybox | =1.13.1 | |
Busybox Busybox | =1.14.0 | |
Busybox Busybox | =1.2.2.1 | |
Busybox Busybox | =1.0.0-pre6 | |
Busybox Busybox | =1.12.1 | |
Busybox Busybox | =1.00 | |
Busybox Busybox | =1.16.1 | |
Busybox Busybox | =1.3.1 | |
Busybox Busybox | =1.15.0 | |
Busybox Busybox | =1.11.2 | |
Busybox Busybox | =1.1.2 | |
Busybox Busybox | =1.0.0-pre10 | |
Busybox Busybox | =1.15.2 | |
Busybox Busybox | =1.0.0-pre9 | |
Busybox Busybox | =1.6.1 | |
Busybox Busybox | =1.9.0 | |
Busybox Busybox | =1.0.0-pre8 | |
Busybox Busybox | =1.17.3 | |
Busybox Busybox | =1.18.3 | |
Busybox Busybox | =1.15.1 | |
Busybox Busybox | =1.10.1 | |
Busybox Busybox | =1.12.3 | |
Busybox Busybox | =1.7.3 | |
Busybox Busybox | =1.14.3 | |
Busybox Busybox | =1.17.4 | |
Busybox Busybox | =1.0.0-rc1 | |
Busybox Busybox | =1.10.3 | |
Busybox Busybox | =1.8.0 | |
Busybox Busybox | =1.18.2 | |
Busybox Busybox | =1.4.2 | |
Busybox Busybox | <=1.19.4 | |
Busybox Busybox | =1.13.3 | |
Busybox Busybox | =1.5.1 | |
Busybox Busybox | =1.16.0 | |
Busybox Busybox | =1.19.3 | |
Busybox Busybox | =1.12.4 | |
Busybox Busybox | =1.0.0-pre5 | |
Busybox Busybox | =1.3.0 | |
Busybox Busybox | =1.6.0 | |
Busybox Busybox | =1.2.2 | |
Busybox Busybox | =1.4.0 | |
Busybox Busybox | =1.18.0 | |
Busybox Busybox | =1.1.1 | |
Busybox Busybox | =1.15.3 | |
Busybox Busybox | =1.14.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.