CVE-2012-2736

Publication date 18 June 2012

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

4.4 · Medium

Score breakdown

In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.

Read the notes from the security team

Status

Package Ubuntu Release Status
network-manager 12.04 LTS precise
Not affected
11.10 oneiric
Fixed 0.9.1.90-0ubuntu5.2
11.04 natty
Fixed 0.8.4~git.20110319t175609.d14809b-0ubuntu3.1
10.04 LTS lucid
Fixed 0.8-0ubuntu3.3
8.04 LTS hardy Ignored end of life
network-manager-applet 12.04 LTS precise
Not affected
11.10 oneiric
Fixed 0.9.1.90-0ubuntu6.1
11.04 natty
Fixed 0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1
10.04 LTS lucid
Fixed 0.8-0ubuntu3.1
8.04 LTS hardy Ignored end of life

Notes


jdstrand

This only affects Ad-Hoc networks that the user creates, not networks the user connects to Per upstream, this is actually a problem with the kernel as of 2.6.30

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
network-manager
network-manager-applet

Severity score breakdown

Parameter Value
Base score 4.4 · Medium
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality Low
Integrity impact Low
Availability impact None
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

References

Related Ubuntu Security Notices (USN)

    • USN-1483-2
    • network-manager-applet vulnerability
    • 27 June 2012
    • USN-1483-1
    • NetworkManager vulnerability
    • 27 June 2012

Other references