CVE-2011-0997

dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
iscdhcp
3.0
iscdhcp
3.0.1
iscdhcp
3.0.1:rc1
iscdhcp
3.0.1:rc10
iscdhcp
3.0.1:rc11
iscdhcp
3.0.1:rc12
iscdhcp
3.0.1:rc13
iscdhcp
3.0.1:rc14
iscdhcp
3.0.1:rc2
iscdhcp
3.0.1:rc5
iscdhcp
3.0.1:rc6
iscdhcp
3.0.1:rc7
iscdhcp
3.0.1:rc8
iscdhcp
3.0.1:rc9
iscdhcp
3.0.2
iscdhcp
3.0.2:b1
iscdhcp
3.0.2:rc1
iscdhcp
3.0.2:rc2
iscdhcp
3.0.2:rc3
iscdhcp
3.0.3
iscdhcp
3.0.3:b1
iscdhcp
3.0.3:b2
iscdhcp
3.0.3:b3
iscdhcp
3.0.4
iscdhcp
3.0.4:b1
iscdhcp
3.0.4:b2
iscdhcp
3.0.4:b3
iscdhcp
3.0.4:rc1
iscdhcp
3.0.5
iscdhcp
3.0.5:rc1
iscdhcp
3.0.6:rc1
iscdhcp
3.1-esv
iscdhcp
3.1.0
iscdhcp
3.1.0:a1
iscdhcp
3.1.0:a2
iscdhcp
3.1.0:a3
iscdhcp
3.1.0:b1
iscdhcp
3.1.0:b2
iscdhcp
3.1.0:rc1
iscdhcp
3.1.1:rc1
iscdhcp
3.1.1:rc2
iscdhcp
3.1.2
iscdhcp
3.1.2:b1
iscdhcp
3.1.2:rc1
iscdhcp
3.1.3
iscdhcp
3.1.3:b1
iscdhcp
3.1.3:rc1
iscdhcp
4.1-esv
iscdhcp
4.1-esv:rc1
iscdhcp
4.2.0
iscdhcp
4.2.0:a1
iscdhcp
4.2.0:a2
iscdhcp
4.2.0:b1
iscdhcp
4.2.0:b2
iscdhcp
4.2.0:p1
iscdhcp
4.2.0:rc1
iscdhcp
4.2.1
iscdhcp
4.2.1:b1
iscdhcp
4.2.1:rc1
debiandebian_linux
5.0
debiandebian_linux
6.0
debiandebian_linux
7.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
9.10
canonicalubuntu_linux
10.04
canonicalubuntu_linux
10.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
isc-dhcp
bullseye
4.4.1-2.3+deb11u2
fixed
bullseye (security)
4.4.1-2.3+deb11u1
fixed
bookworm
4.4.3-P1-2
fixed
sid
4.4.3-P1-5
fixed
trixie
4.4.3-P1-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dhcp3
maverick
Fixed 3.1.3-2ubuntu6.1
released
lucid
Fixed 3.1.3-2ubuntu3.1
released
karmic
Fixed 3.1.2-1ubuntu7.2
released
hardy
Fixed 3.0.6.dfsg-1ubuntu9.2
released
dapper
Fixed 3.0.3-6ubuntu7.2
released
isc-dhcp
maverick
dne
lucid
dne
karmic
dne
hardy
dne
dapper
dne
References