The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
| Software | From | Fixed in |
|---|---|---|
| linux / dhcp6c | - | 2011-07-25.x |
| redhat / enterprise_linux | 4.0 | 4.0.x |
| redhat / enterprise_linux | 5.0 | 5.0.x |