CVE-2018-1000135

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vulnerability appears to have been fixed in Some Ubuntu 16.04 packages were fixed, but later updates removed the fix. cf. https://bugs.launchpad.net/ubuntu/+bug/1754671 an upstream fix does not appear to be available at this time.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-1000135

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2018-1000135.html

OS impact

OSVersionStatusFixed in
arch archfixed1.10.3dev+38+g78ef57197-1
suse slesaffected
debian debianbookwormfixed1.12.0-2
debian debianbullseyefixed1.12.0-2
debian debianforkyfixed1.12.0-2
debian debiansidfixed1.12.0-2
debian debiantrixiefixed1.12.0-2

References

Verify integrity in audit chain (admin only). AS-IS.