Summary
The remote host is missing an update to network-manager-applet announced via advisory USN-727-1.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 7.10:
network-manager-gnome 0.6.5-0ubuntu11~7.10.1
Ubuntu 8.04 LTS:
network-manager-gnome 0.6.6-0ubuntu3.1
Ubuntu 8.10:
network-manager-gnome 0.7~~svn20081020t000444-0ubuntu1.8.10.2
In general, a standard system upgrade is sufficient to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-727-1
Insight
It was discovered that network-manager-applet did not properly enforce permissions when responding to dbus requests. A local user could perform dbus queries to view other users' network connection passwords and pre-shared keys.
(CVE-2009-0365)
It was discovered that network-manager-applet did not properly enforce permissions when responding to dbus modify and delete requests. A local user could use dbus to modify or delete other users' network connections. This issue only applied to Ubuntu 8.10. (CVE-2009-0578)
Severity
Classification
-
CVE CVE-2007-4850, CVE-2008-5005, CVE-2008-5557, CVE-2009-0037, CVE-2009-0365, CVE-2009-0537, CVE-2009-0544, CVE-2009-0578, CVE-2009-0619, CVE-2009-0754, CVE-2009-0775 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities