Описание
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1.2.4-6ubuntu0.1 |
| devel | not-affected | 1.2.6-1 |
| esm-apps/bionic | released | 1.2.4-6ubuntu0.1 |
| esm-apps/xenial | released | 1.1.93-1ubuntu0.1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [0.9.8.6-1ubuntu2.1]] |
| precise/esm | DNE | |
| trusty | released | 0.9.8.6-1ubuntu2.1 |
| trusty/esm | DNE | trusty was released [0.9.8.6-1ubuntu2.1] |
| upstream | released | 1.2.6 |
| xenial | released | 1.1.93-1ubuntu0.1 |
Показывать по
EPSS
7.2 High
CVSS2
7.8 High
CVSS3
Связанные уязвимости
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1 ...
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.
EPSS
7.2 High
CVSS2
7.8 High
CVSS3