Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A privilege escalation flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The root nm-fortisslvpn-service writes VPN connection profile credentials verbatim into a line-oriented configuration file consumed by privileged helper processes, without rejecting embedded carriage-return/line-feed (CR/LF) characters. A local unprivileged user can craft a VPN profile whose credential fields contain CR/LF sequences to inject additional configuration directives, such as pppd-log and pppd-ifname, into this file. By chaining injected directives, an attacker can manipulate /etc/ld.so.preload and achieve arbitrary native code execution as root when the malicious VPN connection is activated.