Bug 1324025 (CVE-2016-0764)
Summary: | CVE-2016-0764 NetworkManager: Race condition allowing info leak | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Adam Mariš <amaris> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | atragler, bgalvani, dcbw, dmoppert, lkundrak, lrintel, rkhan, thaller |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | NetworkManager 1.0.12 | Doc Type: | Bug Fix |
Doc Text: |
A race condition vulnerability was discovered in NetworkManager. Temporary files were created insecurely when saving or updating connection settings, which could allow local users to read connection secrets such as VPN passwords or WiFi keys.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-08 02:50:21 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1324027, 1337774 | ||
Bug Blocks: | 1323912, 1324029 |
Description
Adam Mariš
2016-04-05 11:34:20 UTC
Created NetworkManager tracking bugs for this issue: Affects: fedora-all [bug 1324027] Fix from upstream: https://cgit.freedesktop.org/NetworkManager/NetworkManager/commit/?id=60b7ed3bdc3941a3b7c56824fba4b7291e79041f rhel-5 version 0.7.0 unaffected: the vulnerable behaviour was introduced between 0.7.1 and 0.7.2. From upstream description of the flaw:
> could enable an unprivileged authenticated local user to read connection
> secrets while the connection is being saved.
The opportunity and impact of this vulnerability is very low, so tagging WONTFIX for rhel-6.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:2581 https://rhn.redhat.com/errata/RHSA-2016-2581.html |