2.1
CVSSv2

CVE-2009-4145

Published: 23/12/2009 Updated: 19/09/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome networkmanager 0.7.2

Vendor Advisories

Synopsis Moderate: NetworkManager security update Type/Severity Security Advisory: Moderate Topic Updated NetworkManager packages that fix two security issues are nowavailable for Red Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team ...
It was discovered that NetworkManager did not ensure that the Certification Authority (CA) certificate file remained present when using WPA Enterprise or 8021x networks A remote attacker could use this flaw to spoof the identity of a wireless network and view sensitive information (CVE-2009-4144) ...
Debian Bug report logs - #563371 CVE-2009-4145: information disclosure Package: network-manager-applet; Maintainer for network-manager-applet is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Sat, 2 Jan 2010 11:42:02 UTC Severity: ...
Debian Bug report logs - #560067 CVE-2009-4144: WPA enterprise network not verified when certificate is removed Package: network-manager-gnome; Maintainer for network-manager-gnome is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for network-manager-gnome is src:network-manager-applet (PTS, buildd, ...