USN-727-2: NetworkManager vulnerability

Ubuntu Security Notice USN-727-2

3rd March, 2009

network-manager vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 8.10
  • Ubuntu 6.06 LTS

Software description

  • network-manager

Details

USN-727-1 fixed vulnerabilities in network-manager-applet. This advisory
provides the corresponding updates for NetworkManager.

It was discovered that NetworkManager did not properly enforce permissions when
responding to dbus requests. A local user could perform dbus queries to view
system and user network connection passwords and pre-shared keys.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 8.10:
network-manager 0.7~~svn20081018t105859-0ubuntu1.8.10.2
Ubuntu 6.06 LTS:
network-manager-gnome 0.6.2-0ubuntu7.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system upgrade you need to reboot your computer to
effect the necessary changes.

References

CVE-2009-0365