CVE-2011-2716: Input Validation
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOSTNAME, (2) DOMAINNAME, (3) NISDOMAIN, and (4) TFTPSERVERNAME host name options.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2716?
CVE-2011-2716 is considered to have a moderate severity level due to the potential for remote command execution.
How do I fix CVE-2011-2716?
To fix CVE-2011-2716, update your BusyBox version to 1.20.0 or later, which contains the necessary patches.
Who is affected by CVE-2011-2716?
CVE-2011-2716 affects several versions of BusyBox prior to 1.20.0 and specific firmware implementations such as T-Mobile's TM-AC1900 router.
What are the potential risks of CVE-2011-2716?
The risks associated with CVE-2011-2716 include unauthorized execution of arbitrary commands on affected systems.
What components are primarily involved in CVE-2011-2716?
CVE-2011-2716 primarily involves the DHCP client (udhcpc) and its handling of parameters like HOST_NAME and DOMAIN_NAME.