PT-2011-1203 · Isc+1 · Dhcp+2

Sebastian Krahmer

·

Published

2011-04-08

·

Updated

2024-06-15

·

CVE-2011-0997

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ISC DHCP versions 3.0.x through 4.2.x before 4.2.1-P1 ISC DHCP 3.1-ESV before 3.1-ESV-R1 ISC DHCP 4.1-ESV before 4.1-ESV-R2 dhcp before version 4.2.4 p2
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message. This can be demonstrated by a hostname that is provided to dhclient-script. Multiple vulnerabilities in the dhcp package can lead to disruption of protected information and can be exploited remotely.
Recommendations For ISC DHCP versions 3.0.x through 4.2.x before 4.2.1-P1, update to version 4.2.1-P1 or later. For ISC DHCP 3.1-ESV before 3.1-ESV-R1, update to version 3.1-ESV-R1 or later. For ISC DHCP 4.1-ESV before 4.1-ESV-R2, update to version 4.1-ESV-R2 or later. For dhcp before version 4.2.4 p2, update to version 4.2.4 p2 or later. As a temporary workaround, consider restricting the use of the dhclient-script until a patch is available. Avoid using hostnames that may contain shell metacharacters in the affected DHCP message.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09699
CVE-2011-0997
DSA-2216-1
DSA-2217-1
OPENSUSE-SU-2024:10358-1
RHSA-2011:0428
RHSA-2011:0840
RHSA-2011_0428

Affected Products

Isc Dhcp
Red Hat
Dhcp