Description
nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.
CVSS vector
AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9Complexity: Low
Integrity: None
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-2wgm-5xw3-53m2: nm-connection-editor in NetworkManager (NM) 0↗2022-05-02 ▶ OSVCVE-2009-4145: nm-connection-editor in NetworkManager (NM) 0↗2009-12-23 ▶ CVEListCVE-2009-4145: nm-connection-editor in NetworkManager (NM) 0↗2009-12-23 ▶ 📋Vendor Advisories
3Ubuntunetwork-manager-applet vulnerabilities↗2010-01-13 ▶ Red HatNetworkManager: information disclosure by nm-connection-editor↗2009-12-10 ▶ DebianCVE-2009-4145: network-manager - nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects ove...↗2009 ▶ 💬Community
1BugzillaCVE-2009-4145 NetworkManager: information disclosure by nm-connection-editor↗2009-12-10 ▶