2017-10-16 12:31:07 -04:00
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org" ,
"ID" : "CVE-2011-0997" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a" ,
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
} ,
"vendor_name" : "n/a"
}
]
}
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
"value" : "dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "n/a"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
2018-04-05 09:33:01 -04:00
"name" : "37623" ,
"refsource" : "EXPLOIT-DB" ,
2017-10-16 12:31:07 -04:00
"url" : "https://www.exploit-db.com/exploits/37623/"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "https://bugzilla.redhat.com/show_bug.cgi?id=689832" ,
"refsource" : "CONFIRM" ,
2017-10-16 12:31:07 -04:00
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=689832"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "https://www.isc.org/software/dhcp/advisories/cve-2011-0997" ,
"refsource" : "CONFIRM" ,
2017-10-16 12:31:07 -04:00
"url" : "https://www.isc.org/software/dhcp/advisories/cve-2011-0997"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761" ,
"refsource" : "CONFIRM" ,
2017-10-16 12:31:07 -04:00
"url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "DSA-2216" ,
"refsource" : "DEBIAN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.debian.org/security/2011/dsa-2216"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "DSA-2217" ,
"refsource" : "DEBIAN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.debian.org/security/2011/dsa-2217"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "FEDORA-2011-4897" ,
"refsource" : "FEDORA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057888.html"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "FEDORA-2011-4934" ,
"refsource" : "FEDORA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058279.html"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "GLSA-201301-06" ,
"refsource" : "GENTOO" ,
2017-10-16 12:31:07 -04:00
"url" : "http://security.gentoo.org/glsa/glsa-201301-06.xml"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "HPSBMU02752" ,
"refsource" : "HP" ,
2017-10-16 12:31:07 -04:00
"url" : "http://marc.info/?l=bugtraq&m=133226187115472&w=2"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "SSRT100802" ,
"refsource" : "HP" ,
2017-10-16 12:31:07 -04:00
"url" : "http://marc.info/?l=bugtraq&m=133226187115472&w=2"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "MDVSA-2011:073" ,
"refsource" : "MANDRIVA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2011:073"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2011:0428" ,
"refsource" : "REDHAT" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.redhat.com/support/errata/RHSA-2011-0428.html"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2011:0840" ,
"refsource" : "REDHAT" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.redhat.com/support/errata/RHSA-2011-0840.html"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "SSA:2011-097-01" ,
"refsource" : "SLACKWARE" ,
2017-10-16 12:31:07 -04:00
"url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.593345"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "USN-1108-1" ,
"refsource" : "UBUNTU" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.ubuntu.com/usn/USN-1108-1"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "VU#107886" ,
"refsource" : "CERT-VN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.kb.cert.org/vuls/id/107886"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "47176" ,
"refsource" : "BID" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.securityfocus.com/bid/47176"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "71493" ,
"refsource" : "OSVDB" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.osvdb.org/71493"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "oval:org.mitre.oval:def:12812" ,
"refsource" : "OVAL" ,
2017-10-16 12:31:07 -04:00
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12812"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "1025300" ,
"refsource" : "SECTRACK" ,
2017-10-16 12:31:07 -04:00
"url" : "http://securitytracker.com/id?1025300"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "44037" ,
"refsource" : "SECUNIA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://secunia.com/advisories/44037"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "44048" ,
"refsource" : "SECUNIA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://secunia.com/advisories/44048"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "44089" ,
"refsource" : "SECUNIA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://secunia.com/advisories/44089"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "44090" ,
"refsource" : "SECUNIA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://secunia.com/advisories/44090"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "44103" ,
"refsource" : "SECUNIA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://secunia.com/advisories/44103"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "44127" ,
"refsource" : "SECUNIA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://secunia.com/advisories/44127"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "44180" ,
"refsource" : "SECUNIA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://secunia.com/advisories/44180"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "ADV-2011-0879" ,
"refsource" : "VUPEN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.vupen.com/english/advisories/2011/0879"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "ADV-2011-0886" ,
"refsource" : "VUPEN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.vupen.com/english/advisories/2011/0886"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "ADV-2011-0909" ,
"refsource" : "VUPEN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.vupen.com/english/advisories/2011/0909"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "ADV-2011-0915" ,
"refsource" : "VUPEN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.vupen.com/english/advisories/2011/0915"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "ADV-2011-0926" ,
"refsource" : "VUPEN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.vupen.com/english/advisories/2011/0926"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "ADV-2011-0965" ,
"refsource" : "VUPEN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.vupen.com/english/advisories/2011/0965"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "ADV-2011-1000" ,
"refsource" : "VUPEN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.vupen.com/english/advisories/2011/1000"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "iscdhcp-dhclient-command-execution(66580)" ,
"refsource" : "XF" ,
2017-10-16 12:31:07 -04:00
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/66580"
}
]
}
}