Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A privilege escalation flaw was found in NetworkManager-vpnc, the vpnc VPN plugin for NetworkManager. nm-vpnc-service validates plugin-specific VPN configuration items for embedded newline characters, but omits the top-level NMSettingVpn user-name property from this check. This unvalidated username is later serialized verbatim into vpnc's configuration as an "Xauth username" directive. A local unprivileged user can create a VPN profile whose username contains a newline character followed by a "Password helper" directive, causing the root-privileged vpnc process to parse the injected directive and execute an attacker-chosen helper program with UID/EUID 0 when the malicious VPN connection is activated.
This is a local privilege escalation in software that is installed by default, and archived upstream. Hi Lubomir, what do you want to do here? Add a downstream patch to fix the flaw, or add it to fedora-obsolete-packages? I've removed the package from F45 default install, but it's still going to be around for all users who upgrade from previous Fedora releases unless we add an Obsoletes.
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.