CVE-2018-1111

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1111 Issue Tracking Vendor Advisory
https://access.redhat.com/security/vulnerabilities/3442151 Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1524 Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1461 Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1460 Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1459 Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1458 Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1457 Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1456 Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1455 Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1454 Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1453 Vendor Advisory
http://www.securitytracker.com/id/1040912 Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/44652/ Exploit VDB Entry
http://www.securityfocus.com/bid/104195 Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/44890/ Exploit Third Party Advisory
https://www.tenable.com/security/tns-2018-10
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CDCLLCHYFFXW354HMB5QBXOQOY5BH2EJ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IDJA4QRR74TMXW34Q3DYYFPVBYRTJBI7/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMTTB54QNTPD2SK6UL32EVQHMZP6BUUD/
Configurations

Configuration 1

cpe:2.3:o:fedoraproject:fedora:26:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:27:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization_host:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization:4.2:*:*:*:*:*:*:*

Information

Published : 2018-05-17 04:29

Updated : 2023-02-12 11:32


NVD link : CVE-2018-1111

Mitre link : CVE-2018-1111

Products Affected
No products.
CWE