Re: Command injection in /etc/rc.d/netif
Dag-Erling Smørgrav <[email protected]>
| Newsgroups | gmane.os.freebsd.bugs,gmane.os.freebsd.security.general |
|---|---|
| Message-ID | <[email protected]> |
Nami Arjmandi <[email protected]> writes: > I have found netif script to be susceptible to command injection from > both command line and an arbitrary file name. It's probably happening > in /etc/network.subr but I have not yet been able to patch it. Can you explain exactly where a security boundary is being crossed? DES -- Dag-Erling Smørgrav - [email protected]