CVE-2011-1930: Critical severity Klibc Project Klibc vulnerability
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1930?
CVE-2011-1930 has been classified as a potentially critical vulnerability due to the possibility of remote code execution.
How do I fix CVE-2011-1930?
To mitigate CVE-2011-1930, upgrade to klibc versions 2.0.8-6.1, 2.0.12-1, or 2.0.13-4 or above.
What systems are affected by CVE-2011-1930?
CVE-2011-1930 affects klibc versions 1.5.20 and 1.5.21 on Debian systems.
What type of attack does CVE-2011-1930 enable?
CVE-2011-1930 allows a remote attacker to execute arbitrary code through specially crafted DHCP replies.
Is CVE-2011-1930 a widely known vulnerability?
Yes, CVE-2011-1930 has been documented in multiple databases and is recognized in the cybersecurity community.