LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 04-01-2004, 03:01 PM   #16
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422

All I can say is I do not get it. About the only thing I can think of is is to search with find / -iname dhcp and see if anything interesting crops up. Other than that, I'm completely out of ideas.
 
Old 04-01-2004, 03:03 PM   #17
lostlyre
Member
 
Registered: Mar 2004
Location: Fairfield, OH
Distribution: Gentoo 2005.1 AMD64 2.6.12-r6
Posts: 41

Original Poster
Rep: Reputation: 15
check this out

this was found at:
http://www.mandrakesecure.net/en/adv...MDKSA-2003:003


Quote:
MandrakeSoft Security Advisory MDKSA-2003:003 : dhcpcd

Package name dhcpcd
Date January 9th, 2003
Advisory ID MDKSA-2003:003
Affected versions 7.2, 8.0, 8.1, 8.2, 9.0, Single Network Firewall 7.2, Multi Network Firewall 8.2
Synopsis Updated dhcpcd packages fix character expansion vulnerability


Problem Description

A vulnerability was discovered by Simon Kelley in the dhcpcd DHCP client daemon. dhcpcd has the ability to execute an external script named dhcpcd-.exe when an IP address is assigned to that network interface. The script sources the file /var/lib/dhcpcd/dhcpcd-.info which contains shell variables and DHCP assignment information. The way quotes are handled inside these assignments is flawed, and a malicious DHCP server can execute arbitrary shell commands on the vulnerable DHCP client system. This can also be exploited by an attacker able to spoof DHCP responses.

Mandrake Linux packages contain a sample /etc/dhcpc/dhcpcd.exe file and encourages all users to upgrade immediately. Please note that when you do upgrade, you will have to restart the network for the changes to take proper effect by issuing "service network restart" as root.
I wonder if this means that it's gone or that I have to install it...althought I don't have any packacge called dhcpcd...there's got to be something else driving the dhcp server. I'm on the hunt.

Last edited by lostlyre; 04-01-2004 at 03:07 PM.
 
Old 05-01-2004, 01:53 AM   #18
vanweerd
LQ Newbie
 
Registered: May 2004
Posts: 1

Rep: Reputation: 0
Mandrake 10.0:
For me, /sbin/dhclient did what the missing dhcpcd was mentioned to do.

BTW- for Mandrake, dhcpcd is on the 3 main install disks..if you to configure system etc. and search for it, you can install it from cd. I didn't, because I saw dhclient and it worked for me (for now at least).

Regards,
Nick
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
problem with BMC4318. After installing bcmwl5.inf, modprobe ndiswrapper gives error. jnummela Linux - Wireless Networking 17 11-30-2005 06:58 PM
can't modprobe ndiswrapper with .inf driver installed Andrew Skinner Linux - Wireless Networking 2 06-25-2005 08:10 AM
ndiswrapper throws syntax error when I try to run with my .inf file pfatts Linux - Wireless Networking 8 10-01-2004 04:04 PM
Linux stat to Windows Stat sridurai Programming 3 09-24-2004 04:07 PM
Need Broadcom inf FinalStar Linux - Wireless Networking 1 08-09-2004 12:53 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 07:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration