DHCP Client Code Execution Vulnerability - CVE-2018-1111
In Summary : Red Hat has been made aware of a command injection flaw found in a script included in the DHCP client (dhclient) packages in...
https://updatesinfosec.blogspot.com/2018/05/dhcp-client-code-execution.html
In Summary :
Red Hat has been made aware of a command injection flaw found in a script included in the DHCP client (dhclient) packages in Red Hat Enterprise Linux 6 and 7.
A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager which is configured to obtain network configuration using the DHCP protocol. [...]
kindly refer the following link as follow up :
https://ift.tt/2rJjRaA
Red Hat has been made aware of a command injection flaw found in a script included in the DHCP client (dhclient) packages in Red Hat Enterprise Linux 6 and 7.
A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager which is configured to obtain network configuration using the DHCP protocol. [...]
kindly refer the following link as follow up :
https://ift.tt/2rJjRaA