Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:2307-1

Опубликовано: 13 авг. 2018
Источник: suse-cvrf

Описание

Recommended update for NetworkManager-vpnc

This update for NetworkManager-vpnc fixes the following issues:

Security issue fixed:

  • CVE-2018-10900: Check configurations that contain newline characters and invalidate them to avoid security attacks (bsc#1101147).

This update was imported from the SUSE:SLE-12-SP2:Update update project.

Список пакетов

openSUSE Leap 42.3
NetworkManager-vpnc-1.0.8-7.3.1
NetworkManager-vpnc-gnome-1.0.8-7.3.1
NetworkManager-vpnc-lang-1.0.8-7.3.1

Описание

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.


Затронутые продукты
openSUSE Leap 42.3:NetworkManager-vpnc-1.0.8-7.3.1
openSUSE Leap 42.3:NetworkManager-vpnc-gnome-1.0.8-7.3.1
openSUSE Leap 42.3:NetworkManager-vpnc-lang-1.0.8-7.3.1

Ссылки