First published: Tue Sep 06 2011(Updated: )
The modify_resolvconf_suse script in the vpnc package before 0.5.1-55.10.1 in SUSE Linux Enterprise Desktop 11 SP1 might allow remote attackers to execute arbitrary commands via a crafted DNS domain name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux Enterprise Desktop | =11-sp1 | |
SUSE VPNC | <=0.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2660 has a high severity rating due to its potential to allow remote command execution.
To fix CVE-2011-2660, update the vpnc package to version 0.5.1-55.10.1 or later.
CVE-2011-2660 affects SUSE Linux Enterprise Desktop 11 SP1.
Yes, CVE-2011-2660 can be exploited remotely if a crafted DNS domain name is used.
The vpnc package prior to version 0.5.1-55.10.1 is impacted by CVE-2011-2660.