CVE-2011-3364

Impact:
Important
Public Date:
2011-09-26
Bugzilla:
737338: CVE-2011-3364 NetworkManager: Console user can escalate to root via newlines in ifcfg-rh connection name

The MITRE CVE dictionary describes this issue as:

Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, when PolicyKit is configured to allow users to create new connections, allows local users to execute arbitrary commands via a newline character in the name for a new network connection, which is not properly handled when writing to the ifcfg file.

Find out more about CVE-2011-3364 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Not vulnerable. This issue did not affect the versions of NetworkManager as shipped with Red Hat Enterprise Linux 4 or 5 as they did not include support for writing NetworkManager configurations to the standard /etc/sysconfig/network-scripts/ifcfg-* files.

CVSS v2 metrics

Base Score 6.9
Base Metrics AV:L/AC:M/Au:N/C:C/I:C/A:C
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (NetworkManager) RHSA-2011:1338 2011-09-26

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 5 NetworkManager Not affected
Red Hat Enterprise Linux 4 NetworkManager Not affected

Acknowledgements

Red Hat would like to thank Matt McCutchen for reporting this issue.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.