|
|
| |
|
| |
NetworkManager: privilege escalation
| Package(s): | NetworkManager |
CVE #(s): | CVE-2011-3364
|
| Created: | September 27, 2011 |
Updated: | November 14, 2011 |
| Description: |
From the Red Hat advisory:
An input sanitization flaw was found in the way the ifcfg-rh NetworkManager
plug-in escaped network connection names containing special characters. If
PolicyKit was configured to allow local, unprivileged users to create and
save new network connections, they could create a connection with a
specially-crafted name, leading to the escalation of their privileges.
Note: By default, PolicyKit prevents unprivileged users from creating and
saving network connections. |
| Alerts: |
|
( Log in to post comments)
|
|
|