gcp-dhcp-takeover-code-exec
gcp-dhcp-takeover-code-exec copied to clipboard
How about responsible disclosure too ALL parties involved?
I was considering to contact ISC, and even though their implementation could rely on additional entropy sources, I still think this is not a vulnerability in dhclient, but rather in the special setup of GCP.
There's dhcp#197 submitted for this on ISC systems. It's unfortunate we weren't notified about this earlier.