PT-2018-10193 · Intel+4 · Lldptool+4

Pedrohc

·

Published

2018-08-10

·

Updated

2023-02-12

·

CVE-2018-10932

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions lldptool versions 1.0.1 and older
Description The issue allows an attacker to inject shell control characters into a buffer, potentially impacting the behavior of the terminal, when mngAddr information is displayed. This occurs because lldptool can print a raw, unsanitized attacker-controlled buffer.
Recommendations For versions 1.0.1 and older, as a temporary workaround, consider restricting the display of mngAddr information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

CESA-2019_3673
CVE-2018-10932
RHSA-2019:3673
RHSA-2019_3673
RLSA-2019:3673
SUSE-SU-2021:3520-1
SUSE-SU-2021_3520-1

Affected Products

Centos
Red Hat
Rocky Linux
Suse
Lldptool