CESA-2010:0108 -- centos 5 i386 NetworkManagerID: oval:org.secpod.oval:def:201920 | Date: (C)2012-01-31 (M)2021-06-02 |
Class: PATCH | Family: unix |
NetworkManager is a network link manager that attempts to keep a wired or wireless network connection active at all times. A missing network certificate verification flaw was found in NetworkManager. If a user created a WPA Enterprise or 802.1x wireless network connection that was verified using a Certificate Authority certificate, and then later removed that CA certificate file, NetworkManager failed to verify the identity of the network on the following connection attempts. In these situations, a malicious wireless network spoofing the original network could trick a user into disclosing authentication credentials or communicating over an untrusted network. An information disclosure flaw was found in NetworkManager"s nm-connection-editor D-Bus interface. If a user edited network connection options using nm-connection-editor, a summary of those changes was broadcasted over the D-Bus message bus, possibly disclosing sensitive information to other local users. Users of NetworkManager should upgrade to these updated packages, which contain backported patches to correct these issues.