CVE-2011-0997
ISC Dhcp - Improper Input Validation
Title source: ruleDescription
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.
Exploits (2)
metasploit
WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/lib/rex/proto/dhcp/server.rb
References (35)
... and 15 more
Scores
EPSS
0.7350
EPSS Percentile
98.8%
Details
CWE
CWE-20
Status
published
Products (19)
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
8.04
canonical/ubuntu_linux
9.10
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
10.10
debian/debian_linux
5.0
debian/debian_linux
6.0
debian/debian_linux
7.0
isc/dhcp
3.0
isc/dhcp
3.0.1 (13 CPE variants)
... and 9 more
Published
Apr 08, 2011
Tracked Since
Feb 18, 2026