CVE-2011-0996
Published: 13 April 2011
dhcpcd before 5.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
Priority
Status
Package | Release | Status |
---|---|---|
dhcpcd Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Released
(1:3.2.3-5ubuntu0.1)
|
|
maverick |
Released
(1:3.2.3-7ubuntu0.10.10.1)
|
|
natty |
Released
(1:3.2.3-7ubuntu0.11.04.1)
|
|
oneiric |
Released
(1:3.2.3-9ubuntu0.1)
|
|
precise |
Released
(1:3.2.3-9ubuntu1)
|
|
quantal |
Released
(1:3.2.3-9ubuntu1)
|
|
upstream |
Needs triage
|
|
dhcpcd5 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Ignored
(end of life)
|
|
oneiric |
Not vulnerable
(5.2.12-1)
|
|
precise |
Not vulnerable
(5.2.12-1)
|
|
quantal |
Not vulnerable
(5.2.12-1)
|
|
upstream |
Released
(5.2.12)
|
|
Patches: upstream: http://roy.marples.name/projects/dhcpcd/changeset/c317b39786ac6c3a939dc711db7c78cf099859fd |