This application requires Javascript for optimal performance.

ISC.DHCP.Dhclient.Server.Response.Handling.Command.Injection

Release Date

Aug 08, 2011

Severity

high

Impact

System Compromise: Remote attackers can run arbitrary commands on vulnerable systems.

Description

This indicates an attack attempt against a Command Injection vulnerability in ISC DHCP.

The vulnerability is caused by an error when the vulnerable software handles a malicious DHCP Request.

Affected Products

ISC DHCP dhclient Prior to 3.1-ESV-R1
ISC DHCP dhclient Prior to 4.1-ESV-R2
ISC DHCP dhclient Prior to 4.2.1-P1

Recommended Actions

Upgrade to the latest version.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-0997

Reference/s

http://www.securityfocus.com/bid/47176 (BugTraq)
http://www.vupen.com/english/advisories/2011/0879

Reference: VID-26405