lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.
References
Link | Resource |
---|---|
https://github.com/intel/openlldp/pull/7 | Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10932 | Issue Tracking Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1551623 | Issue Tracking Third Party Advisory |
https://access.redhat.com/errata/RHSA-2019:3673 |
Configurations
Information
Published : 2018-08-21 11:29
Updated : 2023-02-12 15:31
NVD link : CVE-2018-10932
Mitre link : CVE-2018-10932
JSON object : View
CWE
CWE-117
Improper Output Neutralization for Logs
Products Affected
intel
- lldptool