7.5

CVE-2011-0997

dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Dhcp Version 3.0
Isc ≫ Dhcp Version 3.0.1 Update -
Isc ≫ Dhcp Version 3.0.1 Update rc1
Isc ≫ Dhcp Version 3.0.1 Update rc10
Isc ≫ Dhcp Version 3.0.1 Update rc11
Isc ≫ Dhcp Version 3.0.1 Update rc12
Isc ≫ Dhcp Version 3.0.1 Update rc13
Isc ≫ Dhcp Version 3.0.1 Update rc14
Isc ≫ Dhcp Version 3.0.1 Update rc2
Isc ≫ Dhcp Version 3.0.1 Update rc5
Isc ≫ Dhcp Version 3.0.1 Update rc6
Isc ≫ Dhcp Version 3.0.1 Update rc7
Isc ≫ Dhcp Version 3.0.1 Update rc8
Isc ≫ Dhcp Version 3.0.1 Update rc9
Isc ≫ Dhcp Version 3.0.2 Update -
Isc ≫ Dhcp Version 3.0.2 Update b1
Isc ≫ Dhcp Version 3.0.2 Update rc1
Isc ≫ Dhcp Version 3.0.2 Update rc2
Isc ≫ Dhcp Version 3.0.2 Update rc3
Isc ≫ Dhcp Version 3.0.3 Update -
Isc ≫ Dhcp Version 3.0.3 Update b1
Isc ≫ Dhcp Version 3.0.3 Update b2
Isc ≫ Dhcp Version 3.0.3 Update b3
Isc ≫ Dhcp Version 3.0.4 Update -
Isc ≫ Dhcp Version 3.0.4 Update b1
Isc ≫ Dhcp Version 3.0.4 Update b2
Isc ≫ Dhcp Version 3.0.4 Update b3
Isc ≫ Dhcp Version 3.0.4 Update rc1
Isc ≫ Dhcp Version 3.0.5 Update -
Isc ≫ Dhcp Version 3.0.5 Update rc1
Isc ≫ Dhcp Version 3.0.6 Update rc1
Isc ≫ Dhcp Version 3.1-esv
Isc ≫ Dhcp Version 3.1.0 Update -
Isc ≫ Dhcp Version 3.1.0 Update a1
Isc ≫ Dhcp Version 3.1.0 Update a2
Isc ≫ Dhcp Version 3.1.0 Update a3
Isc ≫ Dhcp Version 3.1.0 Update b1
Isc ≫ Dhcp Version 3.1.0 Update b2
Isc ≫ Dhcp Version 3.1.0 Update rc1
Isc ≫ Dhcp Version 3.1.1 Update rc1
Isc ≫ Dhcp Version 3.1.1 Update rc2
Isc ≫ Dhcp Version 3.1.2 Update -
Isc ≫ Dhcp Version 3.1.2 Update b1
Isc ≫ Dhcp Version 3.1.2 Update rc1
Isc ≫ Dhcp Version 3.1.3 Update -
Isc ≫ Dhcp Version 3.1.3 Update b1
Isc ≫ Dhcp Version 3.1.3 Update rc1
Isc ≫ Dhcp Version 4.1-esv Update -
Isc ≫ Dhcp Version 4.1-esv Update rc1
Isc ≫ Dhcp Version 4.2.0 Update -
Isc ≫ Dhcp Version 4.2.0 Update a1
Isc ≫ Dhcp Version 4.2.0 Update a2
Isc ≫ Dhcp Version 4.2.0 Update b1
Isc ≫ Dhcp Version 4.2.0 Update b2
Isc ≫ Dhcp Version 4.2.0 Update p1
Isc ≫ Dhcp Version 4.2.0 Update rc1
Isc ≫ Dhcp Version 4.2.1 Update -
Isc ≫ Dhcp Version 4.2.1 Update b1
Isc ≫ Dhcp Version 4.2.1 Update rc1
Debian ≫ Debian Linux Version 5.0
Debian ≫ Debian Linux Version 6.0
Debian ≫ Debian Linux Version 7.0
Canonical ≫ Ubuntu Linux Version 6.06 SwEdition lts
Canonical ≫ Ubuntu Linux Version 8.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 9.10
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 10.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 84.29% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://marc.info/?l=bugtraq&m=133226187115472&w=2
Third Party Advisory
Mailing List
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057888.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058279.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/44037
Third Party Advisory
http://secunia.com/advisories/44048
Third Party Advisory
http://secunia.com/advisories/44089
Third Party Advisory
http://secunia.com/advisories/44090
Third Party Advisory
http://secunia.com/advisories/44103
Third Party Advisory
http://secunia.com/advisories/44127
Third Party Advisory
http://secunia.com/advisories/44180
Third Party Advisory
http://security.gentoo.org/glsa/glsa-201301-06.xml
Third Party Advisory
http://securitytracker.com/id?1025300
Third Party Advisory
VDB Entry
http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.593345
Third Party Advisory
http://www.debian.org/security/2011/dsa-2216
Third Party Advisory
http://www.debian.org/security/2011/dsa-2217
Third Party Advisory
http://www.kb.cert.org/vuls/id/107886
Third Party Advisory
US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2011:073
Third Party Advisory
http://www.osvdb.org/71493
Broken Link
http://www.redhat.com/support/errata/RHSA-2011-0428.html
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2011-0840.html
Third Party Advisory
http://www.securityfocus.com/bid/47176
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-1108-1
Third Party Advisory
http://www.vupen.com/english/advisories/2011/0879
Permissions Required
http://www.vupen.com/english/advisories/2011/0886
Permissions Required
http://www.vupen.com/english/advisories/2011/0909
Permissions Required
http://www.vupen.com/english/advisories/2011/0915
Permissions Required
http://www.vupen.com/english/advisories/2011/0926
Permissions Required
http://www.vupen.com/english/advisories/2011/0965
Permissions Required
http://www.vupen.com/english/advisories/2011/1000
Permissions Required
https://bugzilla.redhat.com/show_bug.cgi?id=689832
Patch
Third Party Advisory
Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/66580
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12812
Third Party Advisory
https://www.exploit-db.com/exploits/37623/
Third Party Advisory
VDB Entry
https://www.isc.org/software/dhcp/advisories/cve-2011-0997
Patch
Vendor Advisory