CVE-2011-0996

EUVD-2011-1007
dhcpcd before 5.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
roy_marplesdhcpcd
𝑥
≤ 5.2.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dhcpcd
sid
1:10.1.0-1
fixed
trixie
1:10.1.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dhcpcd
dapper
ignored
hardy
ignored
karmic
ignored
lucid
Fixed 1:3.2.3-5ubuntu0.1
released
maverick
Fixed 1:3.2.3-7ubuntu0.10.10.1
released
natty
Fixed 1:3.2.3-7ubuntu0.11.04.1
released
oneiric
Fixed 1:3.2.3-9ubuntu0.1
released
precise
Fixed 1:3.2.3-9ubuntu1
released
quantal
Fixed 1:3.2.3-9ubuntu1
released
dhcpcd5
dapper
dne
hardy
dne
karmic
dne
lucid
dne
maverick
dne
natty
ignored
oneiric
not-affected
precise
not-affected
quantal
not-affected