Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10932

Опубликовано: 21 авг. 2018
Источник: debian

Описание

lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lldpadfixed1.0.1+git20180808.4e642bd-1package

Примечания

  • https://github.com/intel/openlldp/pull/7

  • https://github.com/intel/openlldp/commit/41feb359a9d0082b0bcf68b1f2b37227f02af4f1

  • Terminal emulators need to perform proper escaping

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 7 лет назад

lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.

CVSS3: 4.3
redhat
больше 7 лет назад

lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.

CVSS3: 4.3
nvd
больше 7 лет назад

lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.

CVSS3: 4.3
msrc
больше 4 лет назад

Описание отсутствует

suse-cvrf
больше 4 лет назад

Security update for open-lldp