Related Vulnerabilities: CVE-2018-1000135  

GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN.

Severity Medium

Remote Yes

Type Information disclosure

Description

GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN.

AVG-662 networkmanager 1.10.2-1 1.10.3dev+38+g78ef57197-1 Medium Fixed

https://bugzilla.redhat.com/show_bug.cgi?id=1553634
https://bugzilla.gnome.org/show_bug.cgi?id=746422
https://bugs.launchpad.net/ubuntu/+source/network-manager/+bug/1754671