GNOME NetworkManager nm-connection-editor D-Bus Interface Discloses Configuration Data to Local Users
|
|
SecurityTracker Alert ID: 1023603 |
|
SecurityTracker URL: http://securitytracker.com/id?1023603
|
|
CVE Reference:
CVE-2009-4145
(Links to External Site)
|
Date: Feb 16 2010
|
Impact:
Disclosure of authentication information, Disclosure of system information, Disclosure of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in GNOME NetworkManager. A local user can obtain potentially sensitive configuration information.
When a user edits network connection options using nm-connection-editor, a summary of the changes is broadcast via the D-Bus message bus. A local user can obtain potentially sensitive information, such as wireless network authentication credentials.
|
Impact:
A local user can obtain potentially sensitive configuration information.
|
Solution:
The vendor has issued a source code fix, available at:
http://git.gnome.org/browse/network-manager-applet/commit/?h=NETWORKMANAGER_APPLET_0_7&id=8627880e07c8345f69ed639325280c7f62a8f894
|
Vendor URL: projects.gnome.org/NetworkManager/ (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Linux (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 16 Feb 2010 22:56:28 +0000
Subject: GNOME NetworkManager
|
CVE-2009-4145
http://git.gnome.org/browse/network-manager-applet/commit/?h=NETWORKMANAGER_APPLET_0_7&id=8627880e07c8345f69ed639325280c7f62a8f894
|
|