First published: Mon Apr 16 2018(Updated: )
A command injection flaw was found in the NetworkManager integration script included in the DHCP client packages in Red Hat Enterprise Linux. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject Fedora | =26 | |
Fedoraproject Fedora | =27 | |
Fedoraproject Fedora | =28 | |
Redhat Enterprise Virtualization | =4.0 | |
Redhat Enterprise Virtualization | =4.2 | |
Redhat Enterprise Virtualization Host | =4.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =6.4 | |
Redhat Enterprise Linux | =6.5 | |
Redhat Enterprise Linux | =6.6 | |
Redhat Enterprise Linux | =6.7 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =7.2 | |
Redhat Enterprise Linux | =7.3 | |
Redhat Enterprise Linux | =7.4 | |
Redhat Enterprise Linux | =7.5 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
redhat/dhcp | <12:4.1.1-53.P1.el6_9.4 | 12:4.1.1-53.P1.el6_9.4 |
redhat/dhcp | <12:4.1.1-34.P1.el6_4.2 | 12:4.1.1-34.P1.el6_4.2 |
redhat/dhcp | <12:4.1.1-38.P1.el6_5.1 | 12:4.1.1-38.P1.el6_5.1 |
redhat/dhcp | <12:4.1.1-43.P1.el6_6.2 | 12:4.1.1-43.P1.el6_6.2 |
redhat/dhcp | <12:4.1.1-49.P1.el6_7.1 | 12:4.1.1-49.P1.el6_7.1 |
redhat/dhcp | <12:4.2.5-68.el7_5.1 | 12:4.2.5-68.el7_5.1 |
redhat/dhcp | <12:4.2.5-42.el7_2.1 | 12:4.2.5-42.el7_2.1 |
redhat/dhcp | <12:4.2.5-47.el7_3.1 | 12:4.2.5-47.el7_3.1 |
redhat/dhcp | <12:4.2.5-58.el7_4.4 | 12:4.2.5-58.el7_4.4 |
redhat/imgbased | <0:1.0.16-0.1.el7e | 0:1.0.16-0.1.el7e |
redhat/ovirt-node-ng | <0:4.2.0-0.20170814.0.el7 | 0:4.2.0-0.20170814.0.el7 |
redhat/redhat-release-virtualization-host | <0:4.2-3.0.el7 | 0:4.2-3.0.el7 |
Please access https://access.redhat.com/security/vulnerabilities/3442151 for information on how to mitigate this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2018-1111 is a command injection vulnerability found in the NetworkManager integration script included in the DHCP client.
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier versions are affected by CVE-2018-1111.
CVE-2018-1111 has a severity rating of 7.5, indicating it is critical.
To fix CVE-2018-1111, update the DHCP package to version 12:4.1.1-53.P1.el6_9.4 or higher for Red Hat Enterprise Linux 6, and version 12:4.2.5-68.el7_5.1 or higher for Red Hat Enterprise Linux 7. Additionally, update Fedora to the latest version.
You can find more information about CVE-2018-1111 at the following references: [Reference 1](https://access.redhat.com/security/vulnerabilities/3442151), [Reference 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1567974#c0), [Reference 3](https://src.fedoraproject.org/cgit/rpms/dhcp.git/commit/?id=a0d47e7ac135c54863cb164adb811443f676aa17).