Description
The modify_resolvconf_suse script in the vpnc package before 0.5.1-55.10.1 in SUSE Linux Enterprise Desktop 11 SP1 might allow remote attackers to execute arbitrary commands via a crafted DNS domain name.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/49391
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00029.html
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/651577
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/69514
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/708656
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00028.html
Scores
EPSS
0.0109
EPSS Percentile
78.1%
Details
CWE
CWE-20
Status
published
Products (2)
suse/linux_enterprise_desktop
11 sp1
suse/vpnc
< 0.5.1
Published
Sep 06, 2011
Tracked Since
Feb 18, 2026