CVE Database
/

CVE-2011-3364

Back to search

CVE-2011-3364

Published: Nov 4, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, when PolicyKit is configured to allow users to create new connections, allows local users to execute arbitrary commands via a newline character in the name for a new network connection, which is not properly handled when writing to the ifcfg file.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2011-13425
vendor-advisory
x_refsource_FEDORA
MDVSA-2011:171
vendor-advisory
x_refsource_MANDRIVA
RHSA-2011:1338
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now