CVE-2018-10900: Debian Linux

High severity, CVSS 7.8. EPSS: 3.9% chance of exploitation in the next 30 days.

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Gnome Network Manager Vpnc: before 1.2.6 (fixed in 1.2.6)

Published 2018-07-26. Last modified 2026-06-17.