Back

MEDIUM

NetworkManager: Console user can escalate to root via newlines in ifcfg-rh connection name

Published Nov 4, 2011

Description

Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, when PolicyKit is configured to allow users to create new connections, allows local users to execute arbitrary commands via a newline character in the name for a new network connection, which is not properly handled when writing to the ifcfg file.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of NetworkManager as shipped with Red Hat Enterprise Linux 4 or 5 as they did not include support for writing NetworkManager configurations to the standard /etc/sysconfig/network-scripts/ifcfg-* files.

Metrics

Weaknesses (0)

No CWE recorded.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 4, 2011
Updated Aug 6, 2024
Reserved Aug 30, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 26, 2011