Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pedrohc

#21871of 53,630
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2018-10193
4.3
2018-08-10
Intel · Lldptool · CVE-2018-10932
**Name of the Vulnerable Software and Affected Versions** lldptool versions 1.0.1 and older **Description** The issue allows an attacker to inject shell control characters into a buffer, potentially impacting the behavior of the terminal, when `mngAddr` information is displayed. This occurs because `lldptool` can print a raw, unsanitized attacker-controlled buffer. **Recommendations** For versions 1.0.1 and older, as a temporary workaround, consider restricting the display of `mngAddr` information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2018-8407
6.5
2017-11-20
Mit · Kerberos · CVE-2017-7562
**Name of the Vulnerable Software and Affected Versions** Kerberos versions prior to 1.16.1 **Description** An authentication bypass flaw was found in the way krb5's certauth interface handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and erroneous circumstances. **Recommendations** For versions prior to 1.16.1, update to version 1.16.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the certauth interface until a patch is available.