CVE-2009-0578
published 2009-03-05CVE-2009-0578: GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or…
PriorityP422medium6.2CVSS 2.0
AVLACLAuSCNICAC
EPSS
0.34%
26.6th percentile
GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | network-manager-applet | < network-manager-applet 0.7.0.99-1 (bookworm) | network-manager-applet 0.7.0.99-1 (bookworm) |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:L/Au:S/C:N/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qphg-f927-gw8f: GNOME NetworkManager before 0
ghsa_unreviewed·2022-05-02
CVE-2009-0578 [MEDIUM] GHSA-qphg-f927-gw8f: GNOME NetworkManager before 0
GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.
OSV
CVE-2009-0578: GNOME NetworkManager before 0
osv·2009-03-05·CVSS 6.2
CVE-2009-0578 [MEDIUM] CVE-2009-0578: GNOME NetworkManager before 0
GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.
Ubuntu
network-manager-applet vulnerabilities
vendor_ubuntu·2009-03-03·CVSS 4.6
CVE-2009-0365 [MEDIUM] network-manager-applet vulnerabilities
Title: network-manager-applet vulnerabilities
Summary: network-manager-applet vulnerabilities
It was discovered that network-manager-applet did not properly enforce
permissions when responding to dbus requests. A local user could perform dbus
queries to view other users' network connection passwords and pre-shared keys.
(CVE-2009-0365)
It was discovered that network-manager-applet did not properly enforce
permissions when responding to dbus modify and delete requests. A local user
could use dbus to modify or delete other users' network connections. This issue
only applied to Ubuntu 8.10. (CVE-2009-0578)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
NetworkManager: local users can modify the connection settings
vendor_redhat·2009-03-03·CVSS 6.2
CVE-2009-0578 [MEDIUM] NetworkManager: local users can modify the connection settings
NetworkManager: local users can modify the connection settings
GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.
Debian
CVE-2009-0578: network-manager-applet - GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbu...
vendor_debian·2009·CVSS 6.2
CVE-2009-0578 [MEDIUM] CVE-2009-0578: network-manager-applet - GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbu...
GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.
Scope: local
bookworm: resolved (fixed in 0.7.0.99-1)
bullseye: resolved (fixed in 0.7.0.99-1)
forky: resolved (fixed in 0.7.0.99-1)
sid: resolved (fixed in 0.7.0.99-1)
trixie: resolved (fixed in 0.7.0.99-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlhttp://secunia.com/advisories/34067http://secunia.com/advisories/34473http://www.redhat.com/support/errata/RHSA-2009-0361.htmlhttp://www.securityfocus.com/bid/33966http://www.securitytracker.com/id?1021909http://www.ubuntu.com/usn/USN-727-1https://bugzilla.redhat.com/show_bug.cgi?id=487752https://exchange.xforce.ibmcloud.com/vulnerabilities/49063https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8931http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlhttp://secunia.com/advisories/34067http://secunia.com/advisories/34473http://www.redhat.com/support/errata/RHSA-2009-0361.htmlhttp://www.securityfocus.com/bid/33966http://www.securitytracker.com/id?1021909http://www.ubuntu.com/usn/USN-727-1https://bugzilla.redhat.com/show_bug.cgi?id=487752https://exchange.xforce.ibmcloud.com/vulnerabilities/49063https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8931
2009-03-05
Published