{
  "threat_severity" : "Critical",
  "public_date" : "2018-05-15T12:00:00Z",
  "bugzilla" : {
    "description" : "dhcp: Command injection vulnerability in the DHCP client NetworkManager integration script",
    "id" : "1567974",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1567974"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-77",
  "details" : [ "DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.", "A command injection flaw was found in the NetworkManager integration script included in the DHCP client packages in Red Hat Enterprise Linux. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol." ],
  "statement" : "Red Hat has been made aware of a vulnerability affecting the DHCP client packages as shipped with Red Hat Enterprise Linux 6 and 7. This vulnerability CVE-2018-1111 was rated as having a security impact of Critical. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.\nRed Hat Enterprise Virtualization 4.1 includes the vulnerable components, but the default configuration is not impacted because NetworkManager is turned off in the Management Appliance, and not used in conjunction with DHCP in the Hypervisor. Customers can still obtain the updated packages from Red Hat Enterprise Linux channels using `yum update`, or upgrade to Red Hat Enterprise Virtualization 4.2, which includes the fixed packages.\nRed Hat Enterprise Virtualization 3.6 is not vulnerable as it does not use DHCP.",
  "acknowledgement" : "Red Hat would like to thank Felix Wilhelm (Google Security Team) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1454",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "dhcp-12:4.1.1-53.P1.el6_9.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6.4 Advanced Update Support",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1461",
    "cpe" : "cpe:/o:redhat:rhel_aus:6.4",
    "package" : "dhcp-12:4.1.1-34.P1.el6_4.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6.5 Advanced Update Support",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1460",
    "cpe" : "cpe:/o:redhat:rhel_aus:6.5",
    "package" : "dhcp-12:4.1.1-38.P1.el6_5.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6.6 Advanced Update Support",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1459",
    "cpe" : "cpe:/o:redhat:rhel_aus:6.6",
    "package" : "dhcp-12:4.1.1-43.P1.el6_6.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6.6 Telco Extended Update Support",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1459",
    "cpe" : "cpe:/o:redhat:rhel_tus:6.6",
    "package" : "dhcp-12:4.1.1-43.P1.el6_6.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6.7 Extended Update Support",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1458",
    "cpe" : "cpe:/o:redhat:rhel_eus:6.7",
    "package" : "dhcp-12:4.1.1-49.P1.el6_7.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1453",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "dhcp-12:4.2.5-68.el7_5.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7.2 Advanced Update Support",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1457",
    "cpe" : "cpe:/o:redhat:rhel_aus:7.2",
    "package" : "dhcp-12:4.2.5-42.el7_2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7.2 Telco Extended Update Support",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1457",
    "cpe" : "cpe:/o:redhat:rhel_tus:7.2",
    "package" : "dhcp-12:4.2.5-42.el7_2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1457",
    "cpe" : "cpe:/o:redhat:rhel_e4s:7.2",
    "package" : "dhcp-12:4.2.5-42.el7_2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7.3 Extended Update Support",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1456",
    "cpe" : "cpe:/o:redhat:rhel_eus:7.3",
    "package" : "dhcp-12:4.2.5-47.el7_3.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7.4 Extended Update Support",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1455",
    "cpe" : "cpe:/o:redhat:rhel_eus:7.4",
    "package" : "dhcp-12:4.2.5-58.el7_4.4"
  }, {
    "product_name" : "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1524",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::hypervisor",
    "package" : "imgbased-0:1.0.16-0.1.el7ev",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1524",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::hypervisor",
    "package" : "ovirt-node-ng-0:4.2.0-0.20170814.0.el7",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1524",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::hypervisor",
    "package" : "redhat-release-virtualization-host-0:4.2-3.0.el7",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1524",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::hypervisor",
    "package" : "redhat-virtualization-host-0:4.2-20180508.0",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHSA-2018:1525",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::hypervisor",
    "package" : "rhvm-appliance-0:4.2-20180504.0",
    "impact" : "low"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "dhcp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "dhcp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2018-1111\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-1111\nhttps://access.redhat.com/security/vulnerabilities/3442151" ],
  "csaw" : true,
  "name" : "CVE-2018-1111",
  "mitigation" : {
    "value" : "Please access https://access.redhat.com/security/vulnerabilities/3442151 for information on how to mitigate this issue.",
    "lang" : "en:us"
  }
}