Описание
Recommended update for NetworkManager-vpnc
This update for NetworkManager-vpnc fixes the following issues:
Security issue fixed:
- CVE-2018-10900: Check configurations that contain newline characters and invalidate them to avoid security attacks (bsc#1101147).
This update was imported from the SUSE:SLE-12-SP2:Update update project.
Список пакетов
openSUSE Leap 42.3
NetworkManager-vpnc-1.0.8-7.3.1
NetworkManager-vpnc-gnome-1.0.8-7.3.1
NetworkManager-vpnc-lang-1.0.8-7.3.1
Ссылки
- E-Mail link for openSUSE-SU-2018:2307-1
- SUSE Security Ratings
Описание
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.
Затронутые продукты
openSUSE Leap 42.3:NetworkManager-vpnc-1.0.8-7.3.1
openSUSE Leap 42.3:NetworkManager-vpnc-gnome-1.0.8-7.3.1
openSUSE Leap 42.3:NetworkManager-vpnc-lang-1.0.8-7.3.1
Ссылки
- CVE-2018-10900
- SUSE Bug 1101147