CVE-2018-1111: Command Injection
A command injection flaw was found in the NetworkManager integration script included in the DHCP client packages in Red Hat Enterprise Linux. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.
Other sources
A command injection vulnerability was found in 11-dhclient script provided by dhcp-client located in /etc/NetworkManager/dispatcher.d/11-dhclient. Attacker in local network who is able to spoof DHCP responses or malicious DHCP server can execute arbitrary commands run with root privileges on client system by exploiting this vulnerability.
— Red Hat
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2018-1111?
CVE-2018-1111 is a command injection vulnerability found in the NetworkManager integration script included in the DHCP client.
Who is affected by CVE-2018-1111?
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier versions are affected by CVE-2018-1111.
How severe is CVE-2018-1111?
CVE-2018-1111 has a severity rating of 7.5, indicating it is critical.
How can I fix CVE-2018-1111?
To fix CVE-2018-1111, update the DHCP package to version 12:4.1.1-53.P1.el6_9.4 or higher for Red Hat Enterprise Linux 6, and version 12:4.2.5-68.el7_5.1 or higher for Red Hat Enterprise Linux 7. Additionally, update Fedora to the latest version.
Where can I find more information about CVE-2018-1111?
You can find more information about CVE-2018-1111 at the following references: [Reference 1](https://access.redhat.com/security/vulnerabilities/3442151), [Reference 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1567974#c0), [Reference 3](https://src.fedoraproject.org/cgit/rpms/dhcp.git/commit/?id=a0d47e7ac135c54863cb164adb811443f676aa17).