CVE-2011-0996

dhcpcd before 5.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
roy_marplesdhcpcd
𝑥
≤ 5.2.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dhcpcd
sid
1:10.1.0-1
fixed
trixie
1:10.1.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dhcpcd
quantal
Fixed 1:3.2.3-9ubuntu1
released
precise
Fixed 1:3.2.3-9ubuntu1
released
oneiric
Fixed 1:3.2.3-9ubuntu0.1
released
natty
Fixed 1:3.2.3-7ubuntu0.11.04.1
released
maverick
Fixed 1:3.2.3-7ubuntu0.10.10.1
released
lucid
Fixed 1:3.2.3-5ubuntu0.1
released
karmic
ignored
hardy
ignored
dapper
ignored
dhcpcd5
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
ignored
maverick
dne
lucid
dne
karmic
dne
hardy
dne
dapper
dne