Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2019:3673

Опубликовано: 05 нояб. 2019
Источник: rocky
Оценка: Low

Описание

Low: lldpad security and bug fix update

The lldpad packages provide the Linux user space daemon and configuration tool for Intel's Link Layer Discovery Protocol (LLDP) Agent with Enhanced Ethernet support.

Security Fix(es):

  • lldptool: improper sanitization of shell-escape codes (CVE-2018-10932)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
lldpadaarch6413.git036e314.el8lldpad-1.0.1-13.git036e314.el8.aarch64.rpm
lldpadi68613.git036e314.el8lldpad-1.0.1-13.git036e314.el8.i686.rpm
lldpadx86_6413.git036e314.el8lldpad-1.0.1-13.git036e314.el8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 8 лет назад

lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.

CVSS3: 4.3
redhat
около 8 лет назад

lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.

CVSS3: 4.3
nvd
около 8 лет назад

lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.

CVSS3: 4.3
msrc
около 5 лет назад

lldptool version 1.0.1 and older can print a raw unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.

CVSS3: 4.3
debian
около 8 лет назад

lldptool version 1.0.1 and older can print a raw, unsanitized attacker ...