Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.882878
Kategorie:CentOS Local Security Checks
Titel:CentOS Update for dhclient CESA-2018:1454 centos6
Zusammenfassung:Check the version of dhclient
Beschreibung:Summary:
Check the version of dhclient

Vulnerability Insight:
The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address. The dhcp packages provide a relay agent and ISC DHCP service
required to enable and administer DHCP on a network.

Security Fix(es):

* A command injection flaw was found in the NetworkManager integration
script included in the DHCP client packages in Red Hat Enterprise Linux. A
malicious DHCP server, or an attacker on the local network able to spoof
DHCP responses, could use this flaw to execute arbitrary commands with root
privileges on systems using NetworkManager and configured to obtain network
configuration using the DHCP protocol. (CVE-2018-1111)

Red Hat would like to thank Felix Wilhelm (Google Security Team) for
reporting this issue.

Affected Software/OS:
dhclient on CentOS 6

Solution:
Please install the updated packages.

CVSS Score:
7.9

CVSS Vector:
AV:A/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2018-1111
1040912
http://www.securitytracker.com/id/1040912
104195
http://www.securityfocus.com/bid/104195
44652
https://www.exploit-db.com/exploits/44652/
44890
https://www.exploit-db.com/exploits/44890/
FEDORA-2018-23ca7a6798
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMTTB54QNTPD2SK6UL32EVQHMZP6BUUD/
FEDORA-2018-36058ed9f2
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CDCLLCHYFFXW354HMB5QBXOQOY5BH2EJ/
FEDORA-2018-5392896132
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IDJA4QRR74TMXW34Q3DYYFPVBYRTJBI7/
RHSA-2018:1453
https://access.redhat.com/errata/RHSA-2018:1453
RHSA-2018:1454
https://access.redhat.com/errata/RHSA-2018:1454
RHSA-2018:1455
https://access.redhat.com/errata/RHSA-2018:1455
RHSA-2018:1456
https://access.redhat.com/errata/RHSA-2018:1456
RHSA-2018:1457
https://access.redhat.com/errata/RHSA-2018:1457
RHSA-2018:1458
https://access.redhat.com/errata/RHSA-2018:1458
RHSA-2018:1459
https://access.redhat.com/errata/RHSA-2018:1459
RHSA-2018:1460
https://access.redhat.com/errata/RHSA-2018:1460
RHSA-2018:1461
https://access.redhat.com/errata/RHSA-2018:1461
RHSA-2018:1524
https://access.redhat.com/errata/RHSA-2018:1524
https://access.redhat.com/security/vulnerabilities/3442151
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1111
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
https://www.tenable.com/security/tns-2018-10
CopyrightCopyright (C) 2018 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.