Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

DHCP:OPT:REDHAT-CLIENT-SCRIPT

Severity

Major

Recommended

No

Category

DHCP

Keywords

Red Hat Enterprise Linux Server CVE-2018-1111 Code Execution

Release Date

2018/05/28

Update Number

3069

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

DHCP: Red Hat Enterprise Linux Server CVE-2018-1111 Code Execution


This signature detects attempts to exploit a known vulnerability against Red Hat Enterprise Linux Server. A successful exploit could allow the attacker to inject and execute arbitrary script commands with root privileges on the system.

Extended Description

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.

Affected Products

  • Fedoraproject fedora 26
  • Fedoraproject fedora 27
  • Fedoraproject fedora 28
  • Redhat enterprise_linux 6.0
  • Redhat enterprise_linux 6.4
  • Redhat enterprise_linux 6.5
  • Redhat enterprise_linux 6.6
  • Redhat enterprise_linux 6.7
  • Redhat enterprise_linux 7.0
  • Redhat enterprise_linux 7.2
  • Redhat enterprise_linux 7.3
  • Redhat enterprise_linux 7.4
  • Redhat enterprise_linux 7.5
  • Redhat enterprise_linux_desktop 6.0
  • Redhat enterprise_linux_desktop 7.0
  • Redhat enterprise_linux_server 6.0
  • Redhat enterprise_linux_server 7.0
  • Redhat enterprise_linux_workstation 6.0
  • Redhat enterprise_linux_workstation 7.0
  • Redhat enterprise_virtualization 4.0
  • Redhat enterprise_virtualization 4.2
  • Redhat enterprise_virtualization_host 4.0

References

  • BugTraq: 104195
  • CVE: CVE-2018-1111
  • URL: https://github.com/knqyf263/CVE-2018-1111/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out