Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cmp-3578-qc4p

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

EPSS

Процентиль: 94%
0.14681
Средний

7.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

CVSS3: 7.8
nvd
больше 7 лет назад

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

CVSS3: 7.8
debian
больше 7 лет назад

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1 ...

suse-cvrf
больше 7 лет назад

Recommended update for NetworkManager-vpnc

suse-cvrf
больше 7 лет назад

Recommended update for NetworkManager-vpnc

EPSS

Процентиль: 94%
0.14681
Средний

7.8 High

CVSS3

Дефекты

CWE-78