PT-2018-10193 · Intel+4 · Lldptool+4

Pedrohc

·

Publicado

2018-08-10

·

Atualizado

2023-02-12

·

CVE-2018-10932

CVSS v3.1

4.3

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions lldptool versions 1.0.1 and older
Description The issue allows an attacker to inject shell control characters into a buffer, potentially impacting the behavior of the terminal, when mngAddr information is displayed. This occurs because lldptool can print a raw, unsanitized attacker-controlled buffer.
Recommendations For versions 1.0.1 and older, as a temporary workaround, consider restricting the display of mngAddr information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2019_3673
CVE-2018-10932
RHSA-2019:3673
RHSA-2019_3673
RLSA-2019:3673
SUSE-SU-2021:3520-1
SUSE-SU-2021_3520-1

Produtos afetados

Centos
Red Hat
Rocky Linux
Suse
Lldptool