Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10900

Опубликовано: 26 июл. 2018
Источник: debian

Описание

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
network-manager-vpncfixed1.2.6-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2018/07/20/3

  • https://gitlab.gnome.org/GNOME/NetworkManager-vpnc/commit/07ac18a32b4e361a27ef48ac757d36cbb46e8e12

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

CVSS3: 7.8
nvd
больше 7 лет назад

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

suse-cvrf
больше 7 лет назад

Recommended update for NetworkManager-vpnc

suse-cvrf
больше 7 лет назад

Recommended update for NetworkManager-vpnc

CVSS3: 7.8
github
больше 3 лет назад

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.