Candidate: CVE-2018-10932 PublicDate: 2018-08-21 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10932 https://github.com/intel/openlldp/pull/7 https://github.com/intel/openlldp/commit/41feb359a9d0082b0bcf68b1f2b37227f02af4f1 Description: lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=905901 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N [4.3 MEDIUM] Patches_lldpad: upstream_lldpad: needs-triage precise/esm_lldpad: DNE trusty_lldpad: ignored (reached end-of-life) trusty/esm_lldpad: DNE (trusty was needs-triage) xenial_lldpad: ignored (end of standard support, was needed) bionic_lldpad: needed cosmic_lldpad: ignored (reached end-of-life) disco_lldpad: not-affected (1.0.1+git20180808.4e642bd-1) eoan_lldpad: not-affected (1.0.1+git20180808.4e642bd-1) focal_lldpad: not-affected (1.0.1+git20180808.4e642bd-1) groovy_lldpad: not-affected (1.0.1+git20180808.4e642bd-1) hirsute_lldpad: not-affected (1.0.1+git20180808.4e642bd-1) impish_lldpad: not-affected (1.0.1+git20180808.4e642bd-1) jammy_lldpad: not-affected (1.0.1+git20180808.4e642bd-1) devel_lldpad: not-affected (1.0.1+git20180808.4e642bd-1)