PT-2009-1057 · Gnome+2 · Networkmanager-Glib+7

Dan Williams

·

Published

2009-12-23

·

Updated

2017-09-19

·

CVE-2009-4145

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NetworkManager-gnome version 0.7.0 NetworkManager version 0.7.0 NetworkManager-glib-devel version 0.7.0 NetworkManager-glib version 0.7.0 NetworkManager-devel version 0.7.0
Description The issue concerns multiple vulnerabilities in the NetworkManager package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, the nm-connection-editor in NetworkManager exports connection objects over D-Bus when actions are performed in the connection editor GUI, allowing local users to obtain sensitive information by reading D-Bus signals. For example, an attacker could use dbus-monitor to discover the password for a WiFi network.
Recommendations For NetworkManager-gnome version 0.7.0, consider disabling the nm-connection-editor feature until a patch is available. For NetworkManager version 0.7.0, restrict access to the D-Bus interface to minimize the risk of exploitation. For NetworkManager-glib-devel version 0.7.0, avoid using the D-Bus signals in the affected API endpoints until the issue is resolved. For NetworkManager-glib version 0.7.0, consider disabling the nm-connection-editor function until a patch is available. For NetworkManager-devel version 0.7.0, restrict access to the vulnerable module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06441
BDU:2015-06442
BDU:2015-06443
BDU:2015-06444
BDU:2015-06445
BDU:2015-08569
BDU:2015-08570
BDU:2015-08571
BDU:2015-08572
BDU:2015-08573
CVE-2009-4145
RHSA-2010:0108
RHSA-2010_0108

Affected Products

D-Bus
Networkmanager
Networkmanager-Devel
Networkmanager-Glib
Networkmanager-Glib-Devel
Networkmanager-Gnome
Red Hat
Dbus-Monitor