Loading HuntDB...

GHSA-6cmp-3578-qc4p

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

Related CVEs

Key Information

GHSA ID
GHSA-6cmp-3578-qc4p
Published
May 13, 2022 1:12 AM
Last Modified
May 13, 2022 1:12 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.