SciLinux: CVE-2009-4144 Moderate: NetworkManager SL5.x i386/x86_64
Summary
certificate is removedA missing network certificate verification flaw was found inNetworkManager. If a user created a WPA Enterprise or 802.1x wirelessnetwork connection that was verified using a Certificate Authority (CA)certificate, and then later removed that CA certificate file,NetworkManager failed to verify the identity of the network on thefollowing connection attempts. In these situations, a malicious wirelessnetwork spoofing the original network could trick a user into disclosingauthentication credentials or communicating over an untrusted network.(CVE-2009-4144)An information disclosure flaw was found in NetworkManager'snm-connection-editor D-Bus interface. If a user edited networkconnection options using nm-connection-editor, a summary of thosechanges was broadcasted over the D-Bus message bus, possibly disclosingsensitive information (such as wireless network authenticationcredentials) to other local users. (CVE-2009-4145)SL 5.xSRPMS:NetworkManager-0.7.0-9.el5_4.src.rpmi386:NetworkManager-0.7.0-9.el5_4.i386.rpmNetworkManager-devel-0.7.0-9.el5_4.i386.rpmNetworkManager-glib-0.7.0-9.el5_4.i386.rpmNetworkManager-glib-devel-0.7.0-9.el5_4.i386.rpmNetworkManager-gnome-0.7.0-9.el5_4.i386.rpmx86_64:NetworkManager-0.7.0-9.el5_4.i386.rpmNetworkManager-0.7.0-9.el5_4.x86_64.rpmNetworkManager-devel-0.7.0-9.el5_4.i386.rpmNetworkManager-devel-0.7.0-9.el5_4.x86_64.rpmNetworkManager-glib-0.7.0-9.el5_4.i386.rpmNetworkManager-glib-0.7.0-9.el5_4.x86_64.rpmNetworkManager-glib-devel-0.7.0-9.el5_4.i386.rpmNetworkManager-glib-devel-0.7.0-9.el5_4.x86_64.rpmNetworkManager-gnome-0.7.0-9.el5_4.x86_64.rpm-Connie Sieh-Troy Dawson