DSA-4637-1 network-manager-ssh -- network-manager-sshID: oval:org.secpod.oval:def:604783 | Date: (C)2020-03-10 (M)2022-01-03 |
Class: PATCH | Family: unix |
Kobus van Schoor discovered that network-manager-ssh, a plugin to provide VPN integration for SSH in NetworkManager, is prone to a privilege escalation vulnerability. A local user with privileges to modify a connection can take advantage of this flaw to execute arbitrary commands as root. This update drops support to pass extra SSH options to the ssh invocation.
Platform: |
Debian 10.x |
Debian 9.x |
Product: |
network-manager-ssh |