Posted by Valdis . Kletnieks on Apr 06
Yeah. They shouldn't. Doesn't mean it doesn't manage to happen though.
Sometimes it's harder to defend yourself against the crap sent to you by legit
services than it is defending against a rogue server…
(Yes, I've seen more than misconfigured getup that was serving up a FQDN for
hostname and "" for domainname. You'd think hotels, coffeeshops, and the like
would have enough sense to contract out to…
Source: Re: ISC DHCP Client [3.0.x to 4.2.x] Arbitrary Command Execution (CVE-2011-0997)




