PT-2011-1127 · Red Hat · Networkmanager-Gnome+7
Matt Mccutchen
·
Publicado
2011-09-26
·
Atualizado
2012-01-19
·
CVE-2011-3364
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NetworkManager versions 0.8.1 through 0.9.1
NetworkManager-glib versions 0.8.1
NetworkManager-glib-devel version 0.8.1
NetworkManager-devel version 0.8.1
NetworkManager-gnome version 0.8.1
NetworkManager-debuginfo version 0.8.1
Description
The issue allows local users to execute arbitrary commands via a newline character in the name for a new network connection, which is not properly handled when writing to the ifcfg file. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations
For NetworkManager versions 0.8.1 through 0.9.1, consider disabling the creation of new network connections via PolicyKit until a patch is available.
For NetworkManager-glib versions 0.8.1, NetworkManager-glib-devel version 0.8.1, NetworkManager-devel version 0.8.1, NetworkManager-gnome version 0.8.1, and NetworkManager-debuginfo version 0.8.1, restrict access to the ifcfg file to minimize the risk of exploitation.
Avoid using newline characters in the name for new network connections until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Networkmanager
Networkmanager-Debuginfo
Networkmanager-Devel
Networkmanager-Glib
Networkmanager-Glib-Devel
Networkmanager-Gnome
Policykit
Red Hat