Format: 1.8 Date: Mon, 13 Feb 2012 14:27:54 +0530 Source: dhcpcd Binary: dhcpcd Architecture: i386 Version: 1:3.2.3-7ubuntu0.11.04.1 Distribution: natty Urgency: high Maintainer: Ubuntu/i386 Build Daemon Changed-By: Zubin Mithra Description: dhcpcd - DHCP client for automatically configuring IPv4 networking Launchpad-Bugs-Fixed: 931036 Changes: dhcpcd (1:3.2.3-7ubuntu0.11.04.1) natty-security; urgency=high . * SECURITY UPDATE: dhcpcd before 5.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message. (LP: #931036) - https://build.opensuse.org/package/view_file?file=dhcpcd-3.2.3-option-checks.diff&package=dhcpcd&project=network%3Adhcp&rev=52442e5c1d803d7c1818a920a0bae7f1 - above linked patch(without the additional support for NETBIOS type messages) has been added. - CVE-2011-0996 Checksums-Sha1: aa35877d95abf386f722c0865dde7de8a7b73616 45312 dhcpcd_3.2.3-7ubuntu0.11.04.1_i386.deb Checksums-Sha256: 280d0da128987647b60a35794eac80a60668bb1cb7e6146180f92598b7e5ca2b 45312 dhcpcd_3.2.3-7ubuntu0.11.04.1_i386.deb Files: ec55b2336821a3adf034fc22fdd94b45 45312 net optional dhcpcd_3.2.3-7ubuntu0.11.04.1_i386.deb Original-Maintainer: Simon Kelley