NetworkManager-l2tp 存在一个输入校验不当的漏洞,允许具有创建 VPN 连接权限的本地用户通过提供在有效整数后包含尾部非数字内容的 mru 或 mtu 属性值,注入任意的 pppd 指令。攻击者可以利用未经验证的字符串被逐字写入 pppd 选项文件(通过 write_config_option() 函数)这一机制,注入 plugin 指令,从而导致拥有 root 权限的 pppd 进程加载由攻击者控制的可共享对象,进而实现以 root 权限执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| nm-l2tp | NetworkManager-l2tp | ≤ 1.52.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nm-l2tp | NetworkManager-l2tp | 0 ~ 1.52.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet