CVE-2009-4144

Publication date 23 December 2009

Last updated 24 July 2024


Ubuntu priority

NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x network remains present upon a connection attempt, which might allow remote attackers to obtain sensitive information or cause a denial of service (connectivity disruption) by spoofing the identity of a wireless network.

Read the notes from the security team

Status

Package Ubuntu Release Status
network-manager 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper Ignored end of life
network-manager-applet 9.10 karmic
Not affected
9.04 jaunty
Fixed 0.7.1~rc4.1-0ubuntu2.1
8.10 intrepid
Fixed 0.7~~svn20081020t000444-0ubuntu1.8.10.3
8.04 LTS hardy
Not affected
6.06 LTS dapper Not in release

Notes


mdeslaur

already fixed in 0.8

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
network-manager-applet

References

Related Ubuntu Security Notices (USN)

    • USN-883-1
    • network-manager-applet vulnerabilities
    • 13 January 2010

Other references