PT-2009-1056 · Red Hat · Networkmanager-Gnome+5

Dan Williams

·

Publicado

2009-12-23

·

Atualizado

2017-09-19

·

CVE-2009-4144

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NetworkManager versions 0.7.0 through 0.7.2 NetworkManager-gnome version 0.7.0 NetworkManager-glib version 0.7.0 NetworkManager-glib-devel version 0.7.0 NetworkManager-devel version 0.7.0
Description The issue affects the NetworkManager package, allowing remote attackers to exploit vulnerabilities and potentially disrupt the confidentiality, integrity, and availability of protected information. This can be achieved by spoofing the identity of a wireless network, particularly in WPA Enterprise or 802.1x networks, if the configured Certification Authority (CA) certificate file is not properly ensured to remain present upon a connection attempt.
Recommendations For NetworkManager versions 0.7.0 through 0.7.2, consider updating to a version where the Certification Authority (CA) certificate file remains present upon a connection attempt to prevent spoofing. For NetworkManager-gnome version 0.7.0, restrict access to sensitive information until a patch is available. For NetworkManager-glib version 0.7.0, avoid using the vulnerable package until an update is provided. For NetworkManager-glib-devel version 0.7.0, disable the development package until a secure version is released. For NetworkManager-devel version 0.7.0, refrain from using the development package until a fix is available.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06441
BDU:2015-06442
BDU:2015-06443
BDU:2015-06444
BDU:2015-06445
BDU:2015-08569
BDU:2015-08570
BDU:2015-08571
BDU:2015-08572
BDU:2015-08573
CVE-2009-4144
RHSA-2010:0108
RHSA-2010_0108

Produtos afetados

Networkmanager
Networkmanager-Devel
Networkmanager-Glib
Networkmanager-Glib-Devel
Networkmanager-Gnome
Red Hat