CVE-2011-0997

ISC Dhcp - Improper Input Validation

Title source: rule

Description

dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.

Exploits (2)

exploitdb WORKING POC
by Pierre Kim · textwebappshardware
https://www.exploit-db.com/exploits/37623
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/lib/rex/proto/dhcp/server.rb

References (35)

... and 15 more

Scores

EPSS 0.7350
EPSS Percentile 98.8%

Details

CWE
CWE-20
Status published
Products (19)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 9.10
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 10.10
debian/debian_linux 5.0
debian/debian_linux 6.0
debian/debian_linux 7.0
isc/dhcp 3.0
isc/dhcp 3.0.1 (13 CPE variants)
... and 9 more
Published Apr 08, 2011
Tracked Since Feb 18, 2026