CVE-2009-0578
Summary
| CVE | CVE-2009-0578 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-03-05 02:30:00 UTC |
| Updated | 2017-09-29 01:33:00 UTC |
| Description | GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Ubuntu | Ubuntu Linux | 8.10 | All | All | All |
| Operating System | Ubuntu | Ubuntu Linux | 8.10 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 487752 – (CVE-2009-0578) CVE-2009-0578 NetworkManager: local users can modify the connection settings | CONFIRM | bugzilla.redhat.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:009 | SUSE | lists.opensuse.org | |
| [security-announce] SUSE Security Announcement: dbus-1 (SUSE-SA:2009:013 | SUSE | lists.opensuse.org | |
| Support | REDHAT | www.redhat.com | |
| USN-727-1: network-manager-applet vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | Vendor Advisory |
| GNOME NetworkManager Lets Local Users Modify Network Configuration Settings. - SecurityTracker | SECTRACK | www.securitytracker.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Red Hat update for NetworkManager - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | |
| NetworkManager D-Bus Request Restriction Security Issues - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| NetworkManager Permission Enforcement Multiple Local Vulnrabilities | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.