Vulnerability Bulletins

DSA-4253 network-manager-vpnc - security update

   
Affected software Debian
 
Denis Andzakovic discovered that network-manager-vpnc, a plugin toprovide VPNC support for NetworkManager, is prone to a privilegeescalation vulnerability. A newline character can be used to inject aPassword helper parameter into the configuration data passed to vpnc,allowing a local user with privileges to modify a system connection toexecute arbitrary commands as root.

More info:

https://www.debian.org/security/2018/dsa-4253