Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-0997

72
FAUCET Score

CVE-2011-0997 is a critical vulnerability affecting ISC DHCP client versions 3.0.x through 4.2.x, 3.1-ESV, and 4.1-ESV, including those used in Canonical and Debian Linux distributions. This flaw allows remote attackers to execute arbitrary commands by injecting shell metacharacters into a hostname received via a DHCP message, which is then processed by the dhclient-script. With a CVSS score of 7.5, it presents a high severity risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild or publicly available exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating its perceived importance.

Impacted Technologies

VendorProductVersion(s)CPE
3.0CPE matchmatch criteria
cpe:2.3:a:isc:dhcp:3.0:*:*:*:*:*:*:*
3.0.1CPE matchmatch criteria
cpe:2.3:a:isc:dhcp:3.0.1:-:*:*:*:*:*:*
3.0.1CPE matchmatch criteria
cpe:2.3:a:isc:dhcp:3.0.1:rc1:*:*:*:*:*:*
3.0.1CPE matchmatch criteria
cpe:2.3:a:isc:dhcp:3.0.1:rc10:*:*:*:*:*:*
3.0.1CPE matchmatch criteria
cpe:2.3:a:isc:dhcp:3.0.1:rc11:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
84.29%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.8429 is in the 100th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3 Extended Lifecycle SupportFixed in: dhcp-7:3.0.1-10.3_EL3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: dhcp-7:3.0.1-67.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: dhcp-12:3.0.5-23.el5_6.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: dhcp-12:4.1.1-12.P1.el6_0.4
View patch

Vendor Advisories (1)

redhatCVE-2011-0997Important

dhclient: insufficient sanitization of certain DHCP response values

Apr 5, 2011

References

kb.juniper.net / InfoCenter/index
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2011-April/057888.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2011-April/058279.html
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
secunia.com / advisories/44037
Third Party Advisory
secunia.com / advisories/44048
Third Party Advisory
secunia.com / advisories/44089
Third Party Advisory
secunia.com / advisories/44090
Third Party Advisory
secunia.com / advisories/44103
Third Party Advisory
secunia.com / advisories/44127
Third Party Advisory
secunia.com / advisories/44180
Third Party Advisory
security.gentoo.org / glsa/glsa-201301-06.xml
Third Party Advisory
securitytracker.com / id
Third Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/66580
Third Party AdvisoryVDB Entry
slackware.com / security/viewer.php
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12812
Third Party Advisory
exploit-db.com / exploits/37623
Third Party AdvisoryVDB Entry
isc.org / software/dhcp/advisories/cve-2011-0997
PatchVendor Advisory
debian.org / security/2011/dsa-2216
Third Party Advisory
debian.org / security/2011/dsa-2217
Third Party Advisory
kb.cert.org / vuls/id/107886
Third Party AdvisoryUS Government Resource
mandriva.com / security/advisories
Third Party Advisory
osvdb.org / 71493
Broken Link
redhat.com / support/errata/RHSA-2011-0428.html
Third Party Advisory
redhat.com / support/errata/RHSA-2011-0840.html
Third Party Advisory
securityfocus.com / bid/47176
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-1108-1
Third Party Advisory
vupen.com / english/advisories/2011/0879
Permissions Required
vupen.com / english/advisories/2011/0886
Permissions Required
vupen.com / english/advisories/2011/0909
Permissions Required
vupen.com / english/advisories/2011/0915
Permissions Required
vupen.com / english/advisories/2011/0926
Permissions Required
vupen.com / english/advisories/2011/0965
Permissions Required
vupen.com / english/advisories/2011/1000
Permissions Required