CVE-2011-2660: Input Validation
Published Sep 6, 2011
·Updated
The modifyresolvconfsuse script in the vpnc package before 0.5.1-55.10.1 in SUSE Linux Enterprise Desktop 11 SP1 might allow remote attackers to execute arbitrary commands via a crafted DNS domain name.
Affected Software
2 affected components
SUSE Linux Enterprise Desktop=11-sp1
SUSE vpnc<=0.5.1
Event History
Sep 6, 2011
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2660?
CVE-2011-2660 has a high severity rating due to its potential to allow remote command execution.
2
How do I fix CVE-2011-2660?
To fix CVE-2011-2660, update the vpnc package to version 0.5.1-55.10.1 or later.
3
What versions of SUSE Linux are affected by CVE-2011-2660?
CVE-2011-2660 affects SUSE Linux Enterprise Desktop 11 SP1.
4
Can CVE-2011-2660 be exploited remotely?
Yes, CVE-2011-2660 can be exploited remotely if a crafted DNS domain name is used.
5
What software is impacted by CVE-2011-2660?
The vpnc package prior to version 0.5.1-55.10.1 is impacted by CVE-2011-2660.