Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.882878
Category:CentOS Local Security Checks
Title:CentOS Update for dhclient CESA-2018:1454 centos6
Summary:Check the version of dhclient
Description:Summary:
Check the version of dhclient

Vulnerability Insight:
The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address. The dhcp packages provide a relay agent and ISC DHCP service
required to enable and administer DHCP on a network.

Security Fix(es):

* A command injection flaw was found in the NetworkManager integration
script included in the DHCP client packages in Red Hat Enterprise Linux. A
malicious DHCP server, or an attacker on the local network able to spoof
DHCP responses, could use this flaw to execute arbitrary commands with root
privileges on systems using NetworkManager and configured to obtain network
configuration using the DHCP protocol. (CVE-2018-1111)

Red Hat would like to thank Felix Wilhelm (Google Security Team) for
reporting this issue.

Affected Software/OS:
dhclient on CentOS 6

Solution:
Please install the updated packages.

CVSS Score:
7.9

CVSS Vector:
AV:A/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-1111
1040912
http://www.securitytracker.com/id/1040912
104195
http://www.securityfocus.com/bid/104195
44652
https://www.exploit-db.com/exploits/44652/
44890
https://www.exploit-db.com/exploits/44890/
FEDORA-2018-23ca7a6798
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMTTB54QNTPD2SK6UL32EVQHMZP6BUUD/
FEDORA-2018-36058ed9f2
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CDCLLCHYFFXW354HMB5QBXOQOY5BH2EJ/
FEDORA-2018-5392896132
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IDJA4QRR74TMXW34Q3DYYFPVBYRTJBI7/
RHSA-2018:1453
https://access.redhat.com/errata/RHSA-2018:1453
RHSA-2018:1454
https://access.redhat.com/errata/RHSA-2018:1454
RHSA-2018:1455
https://access.redhat.com/errata/RHSA-2018:1455
RHSA-2018:1456
https://access.redhat.com/errata/RHSA-2018:1456
RHSA-2018:1457
https://access.redhat.com/errata/RHSA-2018:1457
RHSA-2018:1458
https://access.redhat.com/errata/RHSA-2018:1458
RHSA-2018:1459
https://access.redhat.com/errata/RHSA-2018:1459
RHSA-2018:1460
https://access.redhat.com/errata/RHSA-2018:1460
RHSA-2018:1461
https://access.redhat.com/errata/RHSA-2018:1461
RHSA-2018:1524
https://access.redhat.com/errata/RHSA-2018:1524
https://access.redhat.com/security/vulnerabilities/3442151
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1111
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
https://www.tenable.com/security/tns-2018-10
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.