Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.880580
Kategorie:CentOS Local Security Checks
Titel:CentOS Update for NetworkManager CESA-2010:0108 centos5 i386
Zusammenfassung:The remote host is missing an update for the 'NetworkManager'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'NetworkManager'
package(s) announced via the referenced advisory.

Vulnerability Insight:
NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.

A missing network certificate verification flaw was found in
NetworkManager. If a user created a WPA Enterprise or 802.1x wireless
network connection that was verified using a Certificate Authority (CA)
certificate, and then later removed that CA certificate file,
NetworkManager failed to verify the identity of the network on the
following connection attempts. In these situations, a malicious wireless
network spoofing the original network could trick a user into disclosing
authentication credentials or communicating over an untrusted network.
(CVE-2009-4144)

An information disclosure flaw was found in NetworkManager's
nm-connection-editor D-Bus interface. If a user edited network connection
options using nm-connection-editor, a summary of those changes was
broadcasted over the D-Bus message bus, possibly disclosing sensitive
information (such as wireless network authentication credentials) to other
local users. (CVE-2009-4145)

Users of NetworkManager should upgrade to these updated packages, which
contain backported patches to correct these issues.

Affected Software/OS:
NetworkManager on CentOS 5

Solution:
Please install the updated packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-4144
BugTraq ID: 37580
http://www.securityfocus.com/bid/37580
http://www.openwall.com/lists/oss-security/2009/12/16/3
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11315
http://www.redhat.com/support/errata/RHSA-2010-0108.html
http://secunia.com/advisories/38420
SuSE Security Announcement: SUSE-SR:2010:002 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00000.html
Common Vulnerability Exposure (CVE) ID: CVE-2009-4145
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10539
http://secunia.com/advisories/37819
XForce ISS Database: networkmanager-nmconnectioneditor-info-disc(54898)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54898
CopyrightCopyright (c) 2011 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.