Описание
Recommended update for NetworkManager-vpnc
This update for NetworkManager-vpnc fixes the following issues:
Security issue fixed:
- CVE-2018-10900: Check configurations that contain newline characters and invalidate them to avoid security attacks (bsc#1101147).
Список пакетов
SUSE Linux Enterprise Desktop 12 SP3
NetworkManager-vpnc-1.0.8-8.4.2
NetworkManager-vpnc-gnome-1.0.8-8.4.2
NetworkManager-vpnc-lang-1.0.8-8.4.2
SUSE Linux Enterprise Workstation Extension 12 SP3
NetworkManager-vpnc-1.0.8-8.4.2
NetworkManager-vpnc-gnome-1.0.8-8.4.2
NetworkManager-vpnc-lang-1.0.8-8.4.2
Ссылки
- Link for SUSE-SU-2018:2297-1
- E-Mail link for SUSE-SU-2018:2297-1
- SUSE Security Ratings
- SUSE Bug 1101147
- SUSE CVE CVE-2018-10900 page
Описание
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.
Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP3:NetworkManager-vpnc-1.0.8-8.4.2
SUSE Linux Enterprise Desktop 12 SP3:NetworkManager-vpnc-gnome-1.0.8-8.4.2
SUSE Linux Enterprise Desktop 12 SP3:NetworkManager-vpnc-lang-1.0.8-8.4.2
SUSE Linux Enterprise Workstation Extension 12 SP3:NetworkManager-vpnc-1.0.8-8.4.2
Ссылки
- CVE-2018-10900
- SUSE Bug 1101147