CVE-2011-2716
published 2012-07-03CVE-2011-2716: The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2)…
PriorityP342medium6.8CVSS 2.0
AVAACHAuNCCICAC
EPSS
1.80%
76.1th percentile
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| busybox | busybox | <= 1.19.4 | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:A/AC:H/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4fjg-vv5f-pmrp: The DHCP client (udhcpc) in BusyBox before 1
ghsa_unreviewed·2022-05-13
CVE-2011-2716 [MEDIUM] CWE-20 GHSA-4fjg-vv5f-pmrp: The DHCP client (udhcpc) in BusyBox before 1
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
OSV
CVE-2011-2716: The DHCP client (udhcpc) in BusyBox before 1
osv·2012-07-03·CVSS 6.8
CVE-2011-2716 [MEDIUM] CVE-2011-2716: The DHCP client (udhcpc) in BusyBox before 1
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
Red Hat
busybox: udhcpc insufficient checking of DHCP options
vendor_redhat·2011-03-18·CVSS 6.8
CVE-2011-2716 [MEDIUM] busybox: udhcpc insufficient checking of DHCP options
busybox: udhcpc insufficient checking of DHCP options
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
Package: busybox (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2011-2716: busybox - The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to ...
vendor_debian·2011·CVSS 6.8
CVE-2011-2716 [MEDIUM] CVE-2011-2716: busybox - The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to ...
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
Scope: local
bookworm: resolved (fixed in 1:1.20.0-3)
bullseye: resolved (fixed in 1:1.20.0-3)
forky: resolved (fixed in 1:1.20.0-3)
sid: resolved (fixed in 1:1.20.0-3)
trixie: resolved (fixed in 1:1.20.0-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2716 busybox: udhcpc insufficient checking of DHCP options [fedora-all]
bugzilla·2011-08-17·CVSS 6.8
CVE-2011-2716 [MEDIUM] CVE-2011-2716 busybox: udhcpc insufficient checking of DHCP options [fedora-all]
CVE-2011-2716 busybox: udhcpc insufficient checking of DHCP options [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=725364
Please note: this issue affects mu
Bugzilla
CVE-2011-2716 busybox: udhcpc insufficient checking of DHCP options
bugzilla·2011-07-25·CVSS 7.5
CVE-2011-2716 [HIGH] CVE-2011-2716 busybox: udhcpc insufficient checking of DHCP options
CVE-2011-2716 busybox: udhcpc insufficient checking of DHCP options
A missing DHCP option checking / sanitization flaw was reported for multiple DHCP clients. This flaw may allow DHCP server to trick DHCP clients to set e.g. system hostname to a specially crafted value containing shell special characters. Various scripts assume that hostname is trusted, which may lead to code execution when hostname is specially crafted.
This issue was tracked in bug #689832 for ISC dhclient (CVE-2011-0997), which also discussed few other affected clients. This bug is created to track busybox's udhcpc separately.
Upstream bug report:
https://bugs.busybox.net/show_bug.cgi?id=3979
The busybox version in Red Hat Enterprise Linux 4 is not compiled with support for udhcpc. Version shipped with Red Hat Enter
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://downloads.avaya.com/css/P8/documents/100158840http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0810.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2020/Aug/20http://secunia.com/advisories/45363http://www.busybox.net/news.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:129http://www.securityfocus.com/bid/48879https://bugs.busybox.net/show_bug.cgi?id=3979https://seclists.org/bugtraq/2019/Jun/14https://support.t-mobile.com/docs/DOC-21994http://downloads.avaya.com/css/P8/documents/100158840http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0810.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2020/Aug/20http://secunia.com/advisories/45363http://www.busybox.net/news.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:129http://www.securityfocus.com/bid/48879https://bugs.busybox.net/show_bug.cgi?id=3979https://seclists.org/bugtraq/2019/Jun/14https://support.t-mobile.com/docs/DOC-21994
2012-07-03
Published