Fedora 10 : NetworkManager-openconnect-0.7.0.99-1.fc10 / knetworkmanager-0.7-0.8.20080926svn.fc10 / etc (2009-2419)

Medium Nessus Plugin ID 36291

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora host is missing one or more security updates :

NetworkManager-0.7.0.99-1.fc10 :

- Wed Mar 4 2009 Dan Williams <dcbw at redhat.com> - 1:0.7.0.99-1

- nm: make default wired 'Auto ethX' connection modifiable if an enabled system settings plugin supports modifying connections (rh #485555)

- nm: manpage fixes (rh #447233)

- nm: CVE-2009-0365 - GetSecrets disclosure

- applet: CVE-2009-0578 - local users can modify the connection settings

- applet: fix inability to choose WPA Ad-Hoc networks from the menu

- ifcfg-rh: add read-only support for WPA-PSK connections

- ifcfg-rh: revert fix for #441453 (honor localhost) until gdm gets fixed

- Wed Feb 25 2009 Dan Williams <dcbw at redhat.com> - 1:0.7.0.98-1.git20090225

- Fix getting secrets for system connections (rh #486696)

- More compatible modem autodetection

- Better handle minimal ifcfg files

- Mon Feb 23 2009 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1:0.7.0.97-6.git20090220

- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

- Fri Feb 20 2009 Dan Williams <dcbw at redhat.com> - 1:0.7.0.97-5.git20090220

- Use IFF_LOWER_UP for carrier detect instead of IFF_RUNNING

- Add small delay before probing cdc-acm driven mobile broadband devices

- Thu Feb 19 2009 Dan Williams <dcbw at redhat.com> - 1:0.7.0.97-4.git20090219

- Fix PEAP version selection in the applet (rh #468844)

- Match hostname behavior to 'network' service when hostname is localhost (rh #441453)

- Thu Feb 19 2009 Dan Williams <dcbw at redhat.com> - 1:0.7.0.97-2

- Fix 'noreplace' for nm-system-settings.conf

- Wed Feb 18 2009 Dan Williams <dcbw at redhat.com> - 1:0.7.0.97-1

- Update to 0.7.1rc1

- nm: support for Huawei E160G mobile broadband devices (rh #466177)

- nm: fix misleading routing error message (rh #477916)

- nm: fix issues with 32-character SSIDs (rh #485312)

- nm: allow root to activate user connections

- nm: automatic modem detection with udev-extras

- nm: massive manpage rewrite

- applet: fix crash when showing the CA certificate ignore dialog a second time

- applet: clear keyring items when deleting a connection

- applet: fix max signal strength calculation in menu (rh #475123)

- applet: fix VPN export (rh #480496)

- Sat Feb 7 2009 Dan Williams <dcbw at redhat.com> - 1:0.7.0-2.git20090207

- applet: fix blank VPN connection message bubbles

- applet: better handling of VPN routing on update

- applet: silence pointless warning (rh #484136)

- applet: desensitize devices in the menu until they are ready (rh #483879)

- nm: Expose WINS servers in the IP4Config over D-Bus

- nm: Better handling of GSM Mobile Broadband modem initialization

- nm: Handle DHCP Classless Static Routes (RFC 3442)

- nm: Fix Mobile Broadband and PPPoE to always use 'noauth'

- nm: Better compatibility with older dual-SSID AP configurations (rh #445369)

- nm: Mark nm-system-settings.conf as %config (rh #465633)

- nm-tool: Show VPN connection information

- ifcfg-rh: Silence message about ignoring loopback config (rh #484060)

- ifcfg-rh: Fix issue with wrong gateway for system connections (rh #476089)

- Fri Jan 2 2009 Dan Williams <dcbw at redhat.com> - 1:0.7.0-1.git20090102

[plus 32 lines in the Changelog]

knetworkmanager-0.7-0.8.20080926svn.fc10 :

- Tue Mar 3 2009 Dan Williams <dcbw at redhat.com> - 0.7-0.8.20080926svn

- don't send blank passwords in settings (rh #486877)

NetworkManager-vpnc-0.7.0.99-1.fc10 :

- Thu Mar 5 2009 Dan Williams <dcbw at redhat.com> 1:0.7.0.99-1

- Update to 0.7.1rc3

- Mon Feb 23 2009 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1:0.7.0.97-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

- Thu Feb 19 2009 Dan Williams <dcbw at redhat.com> 1:0.7.0.97-1

- Update to 0.7.1rc1

- Handle import/export of 'EnableNat', 'DHGroup', 'SaveUserPassword', and 'EnableLocalLAN'

- Sat Jan 3 2009 Dan Williams <dcbw at redhat.com> 1:0.7.0-1

- Rebuild for updated NetworkManager

- Better handling of passwords that shouldn't be saved

- Fix some specfile issues (rh #477151)

- Fri Nov 21 2008 Dan Williams <dcbw at redhat.com> 1:0.7.0-0.11.svn4326

- Rebuild for updated NetworkManager

- Tue Nov 18 2008 Dan Williams <dcbw at redhat.com> 1:0.7.0-0.11.svn4296

- Rebuild for updated NetworkManager

- Mon Nov 17 2008 Dan Williams <dcbw at redhat.com> 1:0.7.0-0.11.svn4293

- Ensure errors are shown when connection fails (rh #331141)

- Fix failures to ask for passwords on connect (rh #429287)

- Fix routing when concentrator specifies routes (rh #449283)

- Pull in upstream support for tokens and not saving passwords

NetworkManager-openconnect-0.7.0.99-1.fc10 :

- Bug #487722 - CVE-2009-0365 NetworkManager: GetSecrets disclosure

- Bug #487752 - CVE-2009-0578 NetworkManager: local users can modify the connection settings

NetworkManager-openvpn-0.7.0.99-1.fc10 :

- Thu Mar 5 2009 Dan Williams <dcbw at redhat.com> 1:0.7.0.99-1

- Update to 0.7.1rc3

- Mon Feb 23 2009 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1:0.7.0.97-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

- Thu Feb 19 2009 Dan Williams <dcbw at redhat.com> 1:0.7.0.97-1

- Update to 0.7.1rc1

- Handle HMAC Authentication (--auth)

- Handle TAP device subnet masks correctly

- Don't segfault if the connection type is invalid

- Sat Jan 3 2009 Dan Williams <dcbw at redhat.com> 1:0.7.0-18.svn11

- Rebuild for updated NetworkManager

- Fix some specfile issues (rh #477149)

- Sat Dec 20 2008 Christoph Hoger <choeger at cs.tu-berlin.de> 0.7.0-17.svn4326

- removed libpng-devel from BuildRequires, added /usr/share/gnome-vpn-properties/openvpn/ (rh #477149)

- Fri Nov 21 2008 Dan Williams <dcbw at redhat.com> 1:0.7.0-16.svn4326

- Rebuild for updated NetworkManager

NetworkManager-pptp-0.7.0.99-1.fc10 :

- Thu Mar 5 2009 Dan Williams <dcbw at redhat.com> 1:0.7.0.99-1

- Update to 0.7.1rc3

- Mon Feb 23 2009 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1:0.7.0.97-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

- Thu Feb 19 2009 Dan Williams <dcbw at redhat.com> 1:0.7.0.97-1

- Update to 0.7.1rc1

- Set a reasonable MTU

- Ensure 'noauth' is used

- Fix domain-based logins

- Fix saving MPPE values in connection editor

- Sat Jan 3 2009 Dan Williams <dcbw at redhat.com> 1:0.7.0-1.svn16

- Rebuild for updated NetworkManager

- Fix some specfile issues (rh #477153)

- Allow the EAP authentication method

- Fri Nov 21 2008 Dan Williams <dcbw at redhat.com> 1:0.7.0-12.svn4326

- Rebuild for updated NetworkManager

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected packages.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=487722

https://bugzilla.redhat.com/show_bug.cgi?id=487752

https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

http://www.nessus.org/u?eb0cdaaf

http://www.nessus.org/u?5ebfe1ec

http://www.nessus.org/u?2a7d06f9

http://www.nessus.org/u?bfaaf6c0

http://www.nessus.org/u?5645c4cc

http://www.nessus.org/u?be814122

Plugin Details

Severity: Medium

ID: 36291

File Name: fedora_2009-2419.nasl

Version: 1.18

Type: local

Agent: unix

Published: 2009/04/23

Updated: 2019/08/02

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.2

Temporal Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:NetworkManager, p-cpe:/a:fedoraproject:fedora:NetworkManager-openconnect, p-cpe:/a:fedoraproject:fedora:NetworkManager-openvpn, p-cpe:/a:fedoraproject:fedora:NetworkManager-pptp, p-cpe:/a:fedoraproject:fedora:NetworkManager-vpnc, p-cpe:/a:fedoraproject:fedora:knetworkmanager, cpe:/o:fedoraproject:fedora:10

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2009/03/08

Vulnerability Publication Date: 2009/03/04

Exploitable With

CANVAS (CANVAS)

Reference Information

CVE: CVE-2009-0365, CVE-2009-0578

BID: 33966

FEDORA: 2009-2419

CWE: 264