U radu programskog paketa NetworkManager uočena su dva propusta koje lokalni napadač može iskoristiti za zaobilaženje ograničenja i otkrivanje osjetljivih informacija.
Paket:
NetworkManager 0.x
Operacijski sustavi:
Fedora 15
Kritičnost:
6
Problem:
nepravilno rukovanje lozinkama, pogreška u programskoj funkciji, pogreška u programskoj komponenti
Sigurnosne ranjivosti su posljedica pogreške vezane uz "auth_admin" element (PolicyKit) te nepravilnosti u rukovanju lozinkama u funkciji "destroy_one_secret".
Posljedica:
Lokalni napadač ranjivosti može iskoristiti za zaobilaženje ograničenja u sustavu te otkrivanje osjetljivih informacija.
Rješenje:
Svim se korisnicima navedenog programskog paketa savjetuje nadogradnja paketa na novije inačice.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-13388
2011-09-27 22:29:32
--------------------------------------------------------------------------------
Name : NetworkManager
Product : Fedora 15
Version : 0.9.1.90
Release : 1.git20110927.fc15
URL : http://www.gnome.org/projects/NetworkManager/
Summary : Network connection manager and user applications
Description :
NetworkManager is a system network service that manages your network devices
and connections, attempting to keep active network connectivity when available.
It manages ethernet, WiFi, mobile broadband (WWAN), and PPPoE devices, and
provides VPN integration with a variety of different VPN services.
--------------------------------------------------------------------------------
Update Information:
This update fixes security issue in ifcfg-rh plugin (CVE-2011-3364).
In addition, it updates to 0.9.1.90 featuring:
* ability to delete connections from nmcli
* correctly handles IPv6 link-local DNS servers when using the dnsmasq local
caching nameserver plugin
* fixes connection timestamps for VPN connections
* fixes the path of iscsiadm
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 27 2011 JiĹ?Ä
Posljednje sigurnosne preporuke