Table of Contents
Learn about the DHCP vulnerability in red hat linux helps hackers execute, who may be affected, and which practical steps users or administrators can take to reduce exposure.
The DHCP Vulnerability in Red Hat Linux Helps Hackers Execute Remote Code Overview
Security researchers at Google have discovered a serious remote command-line vulnerability on Red Hat Linux's DHCP software and derivative versions of the Fedora operating system.
Placed code CVE-2018-1111, this vulnerability allows an attacker to execute remote code without root privileges on the victim machine.
Whenever the computer joins the network, DHCP software will allow the machine to automatically receive network configuration parameters such as IP addresses and DNS servers from DHCP servers (Dynamic Host Control Protocol).
The vulnerability is on the NetworkManager integration script in the DHCP client packages. Felix Wilhelm from Google's security team discovered that the attacker had a malicious DHCP server or connected to the same network as the victim, which could be exploited by faking DHCP responses, eventually executing the code on the machine. victim.
Update affected DHCP versions to avoid attack
The details of this vulnerability were not disclosed by him and said that the code for proving the PoC was short, including a tweet was enough. Barkın Kılıç, a researcher from Turkey, posted the PoC code on Twitter.
Red Hat confirmed that this vulnerability affects Red Hat Linux 6 and 7 and everyone who is using affected DHCP clients should update the latest version immediately.
'Users should disable or delete affected scripts, but this will prevent some configurations from being given by the DHCP server to the machine, such as the NTP address or NIS server , ' Red Hat said.
Fedora also released new HDCP versions that fix bugs for Fedora 26, 27 and 28.
Other Linux kernels such as OpenSUSE or Ubuntu are not affected by DHCP not using the NetworkManager script by default.
See more:
- Top Linux distros for newbies
- Linux operating system: A strange development path
- Some popular Linux 'distro'
Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.
FAQ
Why does the DHCP Vulnerability in Red Hat Linux Helps Hackers Execute Remote Code matter?
Learn about the DHCP vulnerability in red hat linux helps hackers execute, who may be affected, and which practical steps users or administrators can take to reduce exposure.
Who may be affected by this issue?
The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.
How can users reduce the risk?
Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.
Reader Comments 0
Sign in with email or Google to join the discussion.