Summary
The remote host is missing an update to network-manager announced via advisory USN-727-2.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS:
network-manager-gnome 0.6.2-0ubuntu7.1
Ubuntu 8.10:
network-manager 0.7~~svn20081018t105859-0ubuntu1.8.10.2
In general, a standard system upgrade is sufficient to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-727-2
Insight
USN-727-1 fixed vulnerabilities in network-manager-applet. This advisory provides the corresponding updates for NetworkManager.
It was discovered that NetworkManager did not properly enforce permissions when responding to dbus requests. A local user could perform dbus queries to view system and user network connection passwords and pre-shared keys.
Severity
Classification
-
CVE CVE-2007-4850, CVE-2008-5557, CVE-2009-0365, CVE-2009-0537, CVE-2009-0544, CVE-2009-0619, CVE-2009-0754, CVE-2009-0775 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities