Oval Definition:oval:com.ubuntu.precise:def:20067246000
Revision Date:2012-05-14Version:1
Title:CVE-2006-7246 on Ubuntu 12.04 LTS (precise) - low.
Description:When 802.11X authentication is used (ie WPA Enterprise) NetworkManager did not pin a certificate's subject to an ESSID. A rogue access point could therefore be used to conduct MITM attacks by using any other valid certificate issued by the same CA as used in the original network (CVE-2006-7246). If password based authentication is used (e.g. via PEAP or EAP-TTLS) this means an attacker could sniff and potentially crack the password hashes of the victims.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2006-7246
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND While related to the CVE in some way, the 'network-manager' package in precise is not affected (note: '0.9.4.0-0ubuntu4.1').
  • BACK