GNOME NetworkManager Applet SSL Certificate Validation Security Bypass Vulnerability
BID:37313
Info
GNOME NetworkManager Applet SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 37313 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2009 12:00AM |
| Updated: | Dec 17 2009 04:54PM |
| Credit: | Witold Baryluk |
| Vulnerable: |
GNOME NetworkManager Applet 0.7.2 |
| Not Vulnerable: | |
Discussion
GNOME NetworkManager Applet SSL Certificate Validation Security Bypass Vulnerability
GNOME NetworkManager Applet is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates when connecting to certain wireless networks.
Successful exploits allow attackers to perform man-in-the-middle attacks or impersonate trusted networks, which will aid in further attacks.
NetworkManager Applet 0.7.2 is vulnerable.
GNOME NetworkManager Applet is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates when connecting to certain wireless networks.
Successful exploits allow attackers to perform man-in-the-middle attacks or impersonate trusted networks, which will aid in further attacks.
NetworkManager Applet 0.7.2 is vulnerable.
Exploit / POC
GNOME NetworkManager Applet SSL Certificate Validation Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
GNOME NetworkManager Applet SSL Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
GNOME NetworkManager Applet SSL Certificate Validation Security Bypass Vulnerability
References:
References: