CVE-2011-0997
08.04.2011, 15:17
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.Enginsight
Vendor | Product | Version |
---|---|---|
isc | dhcp | 3.0 |
isc | dhcp | 3.0.1 |
isc | dhcp | 3.0.1:rc1 |
isc | dhcp | 3.0.1:rc10 |
isc | dhcp | 3.0.1:rc11 |
isc | dhcp | 3.0.1:rc12 |
isc | dhcp | 3.0.1:rc13 |
isc | dhcp | 3.0.1:rc14 |
isc | dhcp | 3.0.1:rc2 |
isc | dhcp | 3.0.1:rc5 |
isc | dhcp | 3.0.1:rc6 |
isc | dhcp | 3.0.1:rc7 |
isc | dhcp | 3.0.1:rc8 |
isc | dhcp | 3.0.1:rc9 |
isc | dhcp | 3.0.2 |
isc | dhcp | 3.0.2:b1 |
isc | dhcp | 3.0.2:rc1 |
isc | dhcp | 3.0.2:rc2 |
isc | dhcp | 3.0.2:rc3 |
isc | dhcp | 3.0.3 |
isc | dhcp | 3.0.3:b1 |
isc | dhcp | 3.0.3:b2 |
isc | dhcp | 3.0.3:b3 |
isc | dhcp | 3.0.4 |
isc | dhcp | 3.0.4:b1 |
isc | dhcp | 3.0.4:b2 |
isc | dhcp | 3.0.4:b3 |
isc | dhcp | 3.0.4:rc1 |
isc | dhcp | 3.0.5 |
isc | dhcp | 3.0.5:rc1 |
isc | dhcp | 3.0.6:rc1 |
isc | dhcp | 3.1-esv |
isc | dhcp | 3.1.0 |
isc | dhcp | 3.1.0:a1 |
isc | dhcp | 3.1.0:a2 |
isc | dhcp | 3.1.0:a3 |
isc | dhcp | 3.1.0:b1 |
isc | dhcp | 3.1.0:b2 |
isc | dhcp | 3.1.0:rc1 |
isc | dhcp | 3.1.1:rc1 |
isc | dhcp | 3.1.1:rc2 |
isc | dhcp | 3.1.2 |
isc | dhcp | 3.1.2:b1 |
isc | dhcp | 3.1.2:rc1 |
isc | dhcp | 3.1.3 |
isc | dhcp | 3.1.3:b1 |
isc | dhcp | 3.1.3:rc1 |
isc | dhcp | 4.1-esv |
isc | dhcp | 4.1-esv:rc1 |
isc | dhcp | 4.2.0 |
isc | dhcp | 4.2.0:a1 |
isc | dhcp | 4.2.0:a2 |
isc | dhcp | 4.2.0:b1 |
isc | dhcp | 4.2.0:b2 |
isc | dhcp | 4.2.0:p1 |
isc | dhcp | 4.2.0:rc1 |
isc | dhcp | 4.2.1 |
isc | dhcp | 4.2.1:b1 |
isc | dhcp | 4.2.1:rc1 |
debian | debian_linux | 5.0 |
debian | debian_linux | 6.0 |
debian | debian_linux | 7.0 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 9.10 |
canonical | ubuntu_linux | 10.04 |
canonical | ubuntu_linux | 10.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References