{"id":"CVE-2018-10900","details":"Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.","modified":"2026-09-13T11:45:08.334942120Z","published":"2018-07-26T15:29:00.450Z","related":["SUSE-SU-2018:2297-1","openSUSE-SU-2024:10604-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"https://download.gnome.org/sources/NetworkManager-vpnc/1.2/NetworkManager-vpnc-1.2.6.news"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/07/msg00048.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201808-03"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4253"},{"type":"REPORT","url":"https://bugzilla.novell.com/show_bug.cgi?id=1101147"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10900"},{"type":"FIX","url":"https://gitlab.gnome.org/GNOME/NetworkManager-vpnc/commit/07ac18a32b4"},{"type":"EVIDENCE","url":"https://pulsesecurity.co.nz/advisories/NM-VPNC-Privesc"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/45313/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/networkmanager/networkmanager","events":[{"introduced":"0"},{"fixed":"0001318d9ffc66f003d8270ef7485f07b195616b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.2.6"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:gnome:network_manager_vpnc:*:*:*:*:*:*:*:*"}}],"versions":["1.2.5-dev","1.2.4","1.2.3-dev","1.2.2","1.2.1-dev","1.2.0","1.2-rc2","1.2-rc1","1.2-beta3","1.2-beta2","1.2-beta1","1.1.0-dev","0.9.9.95","0.9.10-beta1","0.9.9.1","0.9.8-beta1","0.9.7.995","0.9.6.0","0.9.6-rc2","0.9.5.96","0.9.6-rc1","0.9.5.95","0.9.4.0","0.9.4-rc1","0.9.3.997","0.9.4-beta1","0.9.3.995","0.9.3.990","0.9.2.0","0.9.2","0.9.2-rc1","0.9.1.95","0.9.2-beta1","0.9.1.90","0.9.0","0.9-rc3","0.8.9997","0.9-rc2","0.8.999","0.9.0-rc1","0.8.998","0.9.0-beta3","0.8.997","0.9.0-beta2","0.8.996","0.9.0-beta1","0.8.995","0.8-rc1","0.7.997"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10900.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}