dhclient in ISC DHCP 3.0.x up to and including 4.2.x prior to 4.2.1-P1, 3.1-ESV prior to 3.1-ESV-R1, and 4.1-ESV prior to 4.1-ESV-R2 allows remote malicious users to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
isc dhcp 3.0 |
||
isc dhcp 3.0.1 |
||
isc dhcp 3.0.2 |
||
isc dhcp 3.0.3 |
||
isc dhcp 3.0.4 |
||
isc dhcp 3.0.5 |
||
isc dhcp 3.0.6 |
||
isc dhcp 3.1-esv |
||
isc dhcp 3.1.0 |
||
isc dhcp 3.1.1 |
||
isc dhcp 3.1.2 |
||
isc dhcp 3.1.3 |
||
isc dhcp 4.1-esv |
||
isc dhcp 4.2.0 |
||
isc dhcp 4.2.1 |
||
debian debian linux 5.0 |
||
debian debian linux 6.0 |
||
debian debian linux 7.0 |
||
canonical ubuntu linux 6.06 |
||
canonical ubuntu linux 8.04 |
||
canonical ubuntu linux 9.10 |
||
canonical ubuntu linux 10.04 |
||
canonical ubuntu linux 10.10 |