dhcpcd before 5.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
https://exchange.xforce.ibmcloud.com/vulnerabilities/66641
https://bugzilla.novell.com/show_bug.cgi?id=675052
http://www.securityfocus.com/bid/47272
http://security.gentoo.org/glsa/glsa-201301-04.xml
http://secunia.com/advisories/44070
http://roy.marples.name/projects/dhcpcd/timeline
http://roy.marples.name/projects/dhcpcd/changeset/c317b39786ac6c3a939dc711db7c78cf099859fd
http://roy.marples.name/archives/dhcpcd-discuss/2011/0326.html