Oval Definition:oval:com.redhat.rhsa:def:20100108
Revision Date:2010-02-16Version:639
Title:RHSA-2010:0108: NetworkManager security update (Moderate)
Description:NetworkManager is a network link manager that attempts to keep a wired or wireless network connection active at all times.

  • A missing network certificate verification flaw was found in NetworkManager. If a user created a WPA Enterprise or 802.1x wireless network connection that was verified using a Certificate Authority (CA) certificate, and then later removed that CA certificate file, NetworkManager failed to verify the identity of the network on the following connection attempts. In these situations, a malicious wireless network spoofing the original network could trick a user into disclosing authentication credentials or communicating over an untrusted network. (CVE-2009-4144)

  • An information disclosure flaw was found in NetworkManager's nm-connection-editor D-Bus interface. If a user edited network connection options using nm-connection-editor, a summary of those changes was broadcasted over the D-Bus message bus, possibly disclosing sensitive information (such as wireless network authentication credentials) to other local users. (CVE-2009-4145)

    Users of NetworkManager should upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-4144
    CVE-2009-4145
    RHSA-2010:0108
    RHSA-2010:0108-01
    RHSA-2010:0108-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • NetworkManager is earlier than 1:0.7.0-9.el5_4
  • AND NetworkManager is signed with Red Hat redhatrelease2 key
  • NetworkManager-devel is earlier than 1:0.7.0-9.el5_4
  • AND NetworkManager-devel is signed with Red Hat redhatrelease2 key
  • NetworkManager-glib is earlier than 1:0.7.0-9.el5_4
  • AND NetworkManager-glib is signed with Red Hat redhatrelease2 key
  • NetworkManager-glib-devel is earlier than 1:0.7.0-9.el5_4
  • AND NetworkManager-glib-devel is signed with Red Hat redhatrelease2 key
  • NetworkManager-gnome is earlier than 1:0.7.0-9.el5_4
  • AND NetworkManager-gnome is signed with Red Hat redhatrelease2 key
  • BACK