The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passed to resolvconf(8) unmodified. resolvconf(8) is a shell script which does not validate its input. A lack of quoting meant that shell commands pass as input to resolvconf(8) may be executed.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 16
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:13.5:-:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:13.5:p1:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:13.5:p2:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:13.5:p3:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:13.5:p4:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:13.5:p5:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:13.5:p6:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:13.5:p7:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:14.3:-:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:14.3:p1:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:14.3:p2:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:14.3:p3:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:14.3:p4:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:14.3:p5:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:14.3:p6:*:*:*:*:*:*
|
— | — |
|
Freebsd Freebsd
cpe:2.3:o:freebsd:freebsd:15.0:-:*:*:*:*:*:*
|
— | — |