Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cmp-3578-qc4p

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

EPSS

Процентиль: 92%
0.05059
Низкий

7.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

CVSS3: 7.8
nvd
около 8 лет назад

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

CVSS3: 7.8
debian
около 8 лет назад

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1 ...

suse-cvrf
около 8 лет назад

Recommended update for NetworkManager-vpnc

suse-cvrf
около 8 лет назад

Recommended update for NetworkManager-vpnc

EPSS

Процентиль: 92%
0.05059
Низкий

7.8 High

CVSS3

Дефекты

CWE-78