Candidate: CVE-2011-1930 PublicDate: 2019-11-14 03:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1930 Description: In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_klibc: upstream: http://git.kernel.org/?p=libs/klibc/klibc.git;a=commit;h=46a0f831582629612f0ff9707ad1292887f26bff upstream_klibc: released (1.5.22-1) hardy_klibc: ignored (reached end-of-life) lucid_klibc: ignored (reached end-of-life) maverick_klibc: ignored (reached end-of-life) natty_klibc: ignored (reached end-of-life) oneiric_klibc: not-affected (1.5.22-1ubuntu2) precise_klibc: not-affected quantal_klibc: not-affected raring_klibc: not-affected saucy_klibc: not-affected trusty_klibc: not-affected trusty/esm_klibc: not-affected utopic_klibc: not-affected vivid_klibc: not-affected devel_klibc: not-affected