Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:2297-1

Опубликовано: 10 авг. 2018
Источник: suse-cvrf

Описание

Recommended update for NetworkManager-vpnc

This update for NetworkManager-vpnc fixes the following issues:

Security issue fixed:

  • CVE-2018-10900: Check configurations that contain newline characters and invalidate them to avoid security attacks (bsc#1101147).

Список пакетов

SUSE Linux Enterprise Desktop 12 SP3
NetworkManager-vpnc-1.0.8-8.4.2
NetworkManager-vpnc-gnome-1.0.8-8.4.2
NetworkManager-vpnc-lang-1.0.8-8.4.2
SUSE Linux Enterprise Workstation Extension 12 SP3
NetworkManager-vpnc-1.0.8-8.4.2
NetworkManager-vpnc-gnome-1.0.8-8.4.2
NetworkManager-vpnc-lang-1.0.8-8.4.2

Описание

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP3:NetworkManager-vpnc-1.0.8-8.4.2
SUSE Linux Enterprise Desktop 12 SP3:NetworkManager-vpnc-gnome-1.0.8-8.4.2
SUSE Linux Enterprise Desktop 12 SP3:NetworkManager-vpnc-lang-1.0.8-8.4.2
SUSE Linux Enterprise Workstation Extension 12 SP3:NetworkManager-vpnc-1.0.8-8.4.2

Ссылки