CVE-2011-3364

NameCVE-2011-3364
DescriptionIncomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, when PolicyKit is configured to allow users to create new connections, allows local users to execute arbitrary commands via a newline character in the name for a new network connection, which is not properly handled when writing to the ifcfg file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
network-manager-applet (PTS)jessie0.9.10.0-2fixed
stretch1.4.4-1+deb9u1fixed
buster1.8.20-1.1fixed
bullseye1.20.0-3fixed
bookworm1.30.0-2fixed
sid, trixie1.36.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
network-manager-appletsource(unstable)(not affected)

Notes

- network-manager-applet <not-affected> (ifcfg-rh plugin not built/included in Debian)

Search for package or bug name: Reporting problems