LWN.net Logo

NetworkManager: privilege escalation

Package(s):NetworkManager CVE #(s):CVE-2011-3364
Created:September 27, 2011 Updated:November 14, 2011
Description: From the Red Hat advisory:

An input sanitization flaw was found in the way the ifcfg-rh NetworkManager plug-in escaped network connection names containing special characters. If PolicyKit was configured to allow local, unprivileged users to create and save new network connections, they could create a connection with a specially-crafted name, leading to the escalation of their privileges. Note: By default, PolicyKit prevents unprivileged users from creating and saving network connections.

Alerts:
Mandriva MDVSA-2011:171 2011-11-11
Fedora FEDORA-2011-13401 2011-09-27
Fedora FEDORA-2011-13388 2011-09-27
Scientific Linux SL-Netw-20110926 2011-09-26
Red Hat RHSA-2011:1338-01 2011-09-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds