ALAS2-2020-1498

Related Vulnerabilities: CVE-2020-10754  

A flaw was found in nmcli, where the command-line interface to the NetworkManager did not accept the 802-1x.ca-path and 802-1x.phase2-ca-path settings when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and an insecure connection occurs. (CVE-2020-10754)

ALAS2-2020-1498


Amazon Linux 2 Security Advisory: ALAS-2020-1498
Advisory Release Date: 2020-10-22 17:09 Pacific
Advisory Updated Date: 2020-10-22 22:43 Pacific
Severity: Medium
References: CVE-2020-10754 

Issue Overview:

A flaw was found in nmcli, where the command-line interface to the NetworkManager did not accept the 802-1x.ca-path and 802-1x.phase2-ca-path settings when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and an insecure connection occurs. (CVE-2020-10754)


Affected Packages:

NetworkManager


Issue Correction:
Run yum update NetworkManager to update your system.

New Packages:
aarch64:
    NetworkManager-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-adsl-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-bluetooth-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-team-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-wifi-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-wwan-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-ppp-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-glib-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-glib-devel-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-libnm-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-libnm-devel-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-tui-1.18.8-1.amzn2.0.1.aarch64
    NetworkManager-debuginfo-1.18.8-1.amzn2.0.1.aarch64

i686:
    NetworkManager-1.18.8-1.amzn2.0.1.i686
    NetworkManager-adsl-1.18.8-1.amzn2.0.1.i686
    NetworkManager-bluetooth-1.18.8-1.amzn2.0.1.i686
    NetworkManager-team-1.18.8-1.amzn2.0.1.i686
    NetworkManager-wifi-1.18.8-1.amzn2.0.1.i686
    NetworkManager-wwan-1.18.8-1.amzn2.0.1.i686
    NetworkManager-ppp-1.18.8-1.amzn2.0.1.i686
    NetworkManager-glib-1.18.8-1.amzn2.0.1.i686
    NetworkManager-glib-devel-1.18.8-1.amzn2.0.1.i686
    NetworkManager-libnm-1.18.8-1.amzn2.0.1.i686
    NetworkManager-libnm-devel-1.18.8-1.amzn2.0.1.i686
    NetworkManager-tui-1.18.8-1.amzn2.0.1.i686
    NetworkManager-debuginfo-1.18.8-1.amzn2.0.1.i686

noarch:
    NetworkManager-config-server-1.18.8-1.amzn2.0.1.noarch
    NetworkManager-dispatcher-routing-rules-1.18.8-1.amzn2.0.1.noarch

src:
    NetworkManager-1.18.8-1.amzn2.0.1.src

x86_64:
    NetworkManager-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-adsl-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-bluetooth-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-team-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-wifi-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-wwan-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-ppp-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-glib-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-glib-devel-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-libnm-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-libnm-devel-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-tui-1.18.8-1.amzn2.0.1.x86_64
    NetworkManager-debuginfo-1.18.8-1.amzn2.0.1.x86_64