Overview
The ISC dhclient contains a vulnerability that could allow a remote attacker to execute arbitrary code on the client machine.
Description
According to ISC: ISC dhclient did not strip or escape certain shell meta-characters in responses from the dhcp server (like hostname) before passing the responses on to dhclient-script. Depending on the script and OS, this can result in execution of exploit code on the client. |
Impact
An unauthenticated remote attacker could cause the ISC dhclient to execute arbitrary code on the client machine. |
Solution
Apply an update |
According to ISC: |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Sebastian Krahmer and Marius Tomaschewski at SUSE Security Team for reporting this vulnerability to Internet Systems Consortium.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2011-0997 |
Severity Metric: | 11.34 |
Date Public: | 2011-04-05 |
Date First Published: | 2011-04-05 |
Date Last Updated: | 2011-05-06 15:22 UTC |
Document Revision: | 11 |