{"id":"DEBIAN-CVE-2011-0997","details":"dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.","modified":"2026-09-19T06:47:30.712226599Z","published":"2011-04-08T15:17:27.387Z","upstream":["CVE-2011-0997"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2011-0997"}],"affected":[{"package":{"name":"isc-dhcp","ecosystem":"Debian:12","purl":"pkg:deb/debian/isc-dhcp?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1-P1-16.1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2011-0997.json"}},{"package":{"name":"isc-dhcp","ecosystem":"Debian:13","purl":"pkg:deb/debian/isc-dhcp?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1-P1-16.1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2011-0997.json"}}],"schema_version":"1.9.0"}