Explore top 10 tips to secure your open-source projects now. Read More
×Several vulnerabilities were discovered in tinc, a Virtual Private Network (VPN) daemon. The Common Vulnerabilities and Exposures project identifies the following problems: . Package : tinc Version : 1.0.24-2+deb8u1 CVE ID : CVE-2018-16737 CVE-2018-16758 Several vulnerabilities were discovered in tinc, a Virtual Private Network (VPN) daemon. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2018-16737 Michael Yonli discovered a flaw in the implementation of the authentication protocol that could allow a remote attacker to establish an authenticated, one-way connection with another node. CVE-2018-16758 Michael Yonli discovered that a man-in-the-middle that has intercepted a TCP connection might be able to disable encryption of UDP packets sent by a node. For Debian 8 "Jessie", these problems have been fixed in version 1.0.24-2+deb8u1. We recommend that you upgrade your tinc packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- Met vriendelijke groet / with kind regards, Guus Sliepen . Package : tinc Version : 1.0.24-2+deb8u1 CVE ID : CVE-2018-16737 CVE-2018-16758 Several vulnerabilit. vulnerabilities, virtual, private, network, (vpn), daemon, common. . Severity: Important. LinuxSecurity.com Team
Denis Andzakovic discovered that network-manager-vpnc, a plugin to provide VPNC support for NetworkManager, is prone to a privilege escalation vulnerability. A newline character can be used to inject a . Package : network-manager-vpnc Version : 0.9.10.0-1+deb8u1 CVE ID : CVE-2018-10900 Debian Bug : 904255 Denis Andzakovic discovered that network-manager-vpnc, a plugin to provide VPNC support for NetworkManager, is prone to a privilege escalation vulnerability. A newline character can be used to inject a Password helper parameter into the configuration data passed to vpnc, allowing a local user with privileges to modify a system connection to execute arbitrary commands as root. For Debian 8 "Jessie", this problem has been fixed in version 0.9.10.0-1+deb8u1. We recommend that you upgrade your network-manager-vpnc packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
Update to 1.2.6 to fix a local authenticated privilege escalation bug (CVE-2018-10900). The issue has been discovered and responsibly disclosed by Denis Andzakovic: https://pulsesecurity.co.nz/advisories/NM-VPNC-Privesc. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-ac02463f82 2018-07-26 14:06:30.015804 --------------------------------------------------------------------------------Name : NetworkManager-vpnc Product : Fedora 27 Version : 1.2.6 Release : 1.fc27 URL : https://wiki.gnome.org/Apps Summary : NetworkManager VPN plugin for vpnc Description : This package contains software for integrating VPN capabilities with the vpnc server with NetworkManager. --------------------------------------------------------------------------------Update Information: Update to 1.2.6 to fix a local authenticated privilege escalation bug (CVE-2018-10900). The issue has been discovered and responsibly disclosed by Denis Andzakovic: https://pulsesecurity.co.nz/advisories/NM-VPNC-Privesc --------------------------------------------------------------------------------ChangeLog: * Fri Jul 20 2018 Lubomir Rintel - 1.2.6-1 - Update to 1.2.6 release - Fix a local authenticated privilege escalation bug (CVE-2018-10900) * Thu Jul 12 2018 Fedora Release Engineering - 1:1.2.4-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Wed Feb 7 2018 Fedora Release Engineering - 1:1.2.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Wed Jan 31 2018 Igor Gnatenko - 1:1.2.4-6 - Remove obsolete scriptlets * Thu Nov 30 2017 Lubomir Rintel - 1.2.4-5 - Drop libnm-glib for Fedora 28 --------------------------------------------------------------------------------References: [ 1 ] Bug #1605919 - CVE-2018-10900 NetworkManager-vpnc: privilege escalation allows to execute arbitrary commands as root https://bugzilla.redhat.com/show_bug.cgi?id=1605919 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-ac02463f82' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to NetworkManager 1.2-beta3. Upstream release announcement: https://mail.gnome.org/archives/networkmanager-list/2016-March/msg00164.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-cd218eef79 2016-04-02 15:48:47.755168 -------------------------------------------------------------------------------- Name : NetworkManager-vpnc Product : Fedora 24 Version : 1.2.0 Release : 0.4.beta3.fc24 URL : https://wiki.gnome.org/Apps Summary : NetworkManager VPN plugin for vpnc Description : This package contains software for integrating VPN capabilities with the vpnc server with NetworkManager. -------------------------------------------------------------------------------- Update Information: Update to NetworkManager 1.2-beta3. Upstream release announcement: https://mail.gnome.org/archives/networkmanager-list/2016-March/msg00164.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #756418 - CVE-2006-7246 NetworkManager, wpa_supplicant (WPA-Enterprise): Verify that the certificate is from trusted CA and matches the specified subject https://bugzilla.redhat.com/show_bug.cgi?id=756418 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update NetworkManager-vpnc' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.