First published: Wed Nov 27 2019(Updated: )
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux DHCPv6 Client (dhcp6c) | <=2011-07-25 | |
Red Hat Enterprise Linux | =4.0 | |
Red Hat Enterprise Linux | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2717 has a moderate severity rating due to the potential for remote command execution.
To fix CVE-2011-2717, upgrade to the latest version of the dhcp6c client that addresses this vulnerability.
CVE-2011-2717 affects the dhcp6c client as used in Linux distributions and specifically Red Hat Enterprise Linux versions 4.0 and 5.0.
CVE-2011-2717 is a command injection vulnerability that allows remote DHCP servers to execute arbitrary commands.
The implications of CVE-2011-2717 include the potential compromise of systems due to unauthorized command execution through DHCP.