USN-727-1: network-manager-applet vulnerabilities
3 March 2009
network-manager-applet vulnerabilities
Releases
Packages
Details
It was discovered that network-manager-applet did not properly enforce
permissions when responding to dbus requests. A local user could perform dbus
queries to view other users' network connection passwords and pre-shared keys.
(CVE-2009-0365)
It was discovered that network-manager-applet did not properly enforce
permissions when responding to dbus modify and delete requests. A local user
could use dbus to modify or delete other users' network connections. This issue
only applied to Ubuntu 8.10. (CVE-2009-0578)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 8.10
Ubuntu 8.04
Ubuntu 7.10
In general, a standard system upgrade is sufficient to effect the
necessary changes.
References
Related notices
- USN-727-2: network-manager, network-manager-gnome