PT-2011-1203 · Isc+1 · Dhcp+2

Sebastian Krahmer

·

Publicado

2011-04-08

·

Atualizado

2024-06-15

·

CVE-2011-0997

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ISC DHCP versions 3.0.x through 4.2.x before 4.2.1-P1 ISC DHCP 3.1-ESV before 3.1-ESV-R1 ISC DHCP 4.1-ESV before 4.1-ESV-R2 dhcp before version 4.2.4 p2
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message. This can be demonstrated by a hostname that is provided to dhclient-script. Multiple vulnerabilities in the dhcp package can lead to disruption of protected information and can be exploited remotely.
Recommendations For ISC DHCP versions 3.0.x through 4.2.x before 4.2.1-P1, update to version 4.2.1-P1 or later. For ISC DHCP 3.1-ESV before 3.1-ESV-R1, update to version 3.1-ESV-R1 or later. For ISC DHCP 4.1-ESV before 4.1-ESV-R2, update to version 4.1-ESV-R2 or later. For dhcp before version 4.2.4 p2, update to version 4.2.4 p2 or later. As a temporary workaround, consider restricting the use of the dhclient-script until a patch is available. Avoid using hostnames that may contain shell metacharacters in the affected DHCP message.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09699
CVE-2011-0997
DSA-2216-1
DSA-2217-1
OPENSUSE-SU-2024:10358-1
RHSA-2011:0428
RHSA-2011:0840
RHSA-2011_0428

Produtos afetados

Isc Dhcp
Red Hat
Dhcp