Remote Command Execution Vulnerability in ISC DHCP Client
CVE-2011-0997

Currently unrated

Key Information:

Vendor

Isc

Status
Vendor
CVE Published:
8 April 2011

What is CVE-2011-0997?

The ISC DHCP Client, specifically versions ranging from 3.0.x to 4.2.x before 4.2.1-P1, contains a vulnerability that permits remote attackers to execute arbitrary commands. This can be achieved through the insertion of shell metacharacters within a hostname supplied in a DHCP message to dhclient. By exploiting this flaw, an attacker can manipulate the system to execute unintended commands, potentially leading to unauthorized access or control over the affected system.

References

EPSS Score

71% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.