--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2015-7623
2015-05-06 06:01:08
--------------------------------------------------------------------------------

Name        : NetworkManager
Product     : Fedora 21
Version     : 0.9.10.2
Release     : 5.fc21
URL         : https://wiki.gnome.org/Apps
Summary     : Network connection manager and user applications
Description :
NetworkManager is a system service that manages network interfaces and
connections based on user or automatic configuration. It supports
Ethernet, Bridge, Bond, VLAN, Team, InfiniBand, Wi-Fi, mobile broadband
(WWAN), PPPoE and other devices, and supports a variety of different VPN
services.

--------------------------------------------------------------------------------
Update Information:

This update for NetworkManager fixes a number of bugs and a low-impact security issue for IPv6.
--------------------------------------------------------------------------------
ChangeLog:

* Mon May 11 2015 Lubomir Rintel  - 1:0.9.10.2-5
- The split DNS patches are now upstream (rh #1161232)
* Wed May  6 2015 Lubomir Rintel  - 1:0.9.10.2-4
- Fix split DNS configuration with dnsmasq and VPN connections (rh #1161232)
- Fix indication that a WiFi plugin is missing (rh #1168573)
- Don't let IPv6 Router Advertisements lower Hop Limit (CVE-2015-2924) (rh #1209903)
- User a proper SONAME when loading libnl (rh #1205195)
* Fri Mar 20 2015 Jiří Klimeš  - 1:0.9.10.2-3
- Fix NetworkManager loop when 0.0.0.0/1 is added (rh #1203924)
* Tue Mar 17 2015 Stef Walter  - 1:0.9.10.2-3
- Fix dbus-glib dependency
* Mon Mar 16 2015 Dan Williams  - 1:0.9.10.2-2
- Turn off keepalive for connectivity checking
* Wed Mar  4 2015 Dan Williams  - 1:0.9.10.2-1
- Update to 0.9.10.2 release
* Thu Feb 19 2015 Dan Williams  - 1:0.9.10.1-3
- Update to 0.9.10.2 pre-release snapshot
* Fri Jan 23 2015 Lubomir Rintel  - 1:0.9.10.1-2
- Update to 0.9.10.1, a 0.9.10.2 release candidate 1 tarball
* Thu Jan 15 2015 Jiří Klimeš  - 1:0.9.10.1-1.4.20150115git
- connectivity: fix an connectivity check endless loop (bgo #742823)
* Thu Jan 15 2015 Jiří Klimeš  - 1:0.9.10.1-1.3.20150115git
- update to latest snapshot of 0.9.10
- dhcp: fix connection failures due to stale dhclient lease (rh #1181477)
* Fri Jan  9 2015 Jiří Klimeš  - 1:0.9.10.1-1.2.20150109git
- dhcp: fix killing wrong process ID on dhclient release (rh #1179913)
* Mon Jan  5 2015 Jiří Klimeš  - 1:0.9.10.1-1.git20150105
- update to latest snapshot of 0.9.10
- dhcp: fix dhclient abnormal exit due to SIGPIPE (bgo #735962) (rh #1178666)
* Mon Nov 24 2014 Jiří Klimeš  - 1:0.9.10.0-14.git20140704
- vpn: propagate daemon exec error correctly (bgo #739436)
- core: do not assert when a device is enslaved externally (rh #1167345)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1209902 - CVE-2015-2924 NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements
        https://bugzilla.redhat.com/show_bug.cgi?id=1209902
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update NetworkManager' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/

Fedora 21: NetworkManager Security Update

May 17, 2015
This update for NetworkManager fixes a number of bugs and a low-impact security issue for IPv6.

Summary

NetworkManager is a system service that manages network interfaces and

connections based on user or automatic configuration. It supports

Ethernet, Bridge, Bond, VLAN, Team, InfiniBand, Wi-Fi, mobile broadband

(WWAN), PPPoE and other devices, and supports a variety of different VPN

services.

Update Information:

This update for NetworkManager fixes a number of bugs and a low-impact security issue for IPv6.

Change Log

* Mon May 11 2015 Lubomir Rintel - 1:0.9.10.2-5 - The split DNS patches are now upstream (rh #1161232) * Wed May 6 2015 Lubomir Rintel - 1:0.9.10.2-4 - Fix split DNS configuration with dnsmasq and VPN connections (rh #1161232) - Fix indication that a WiFi plugin is missing (rh #1168573) - Don't let IPv6 Router Advertisements lower Hop Limit (CVE-2015-2924) (rh #1209903) - User a proper SONAME when loading libnl (rh #1205195) * Fri Mar 20 2015 Jiří Klimeš - 1:0.9.10.2-3 - Fix NetworkManager loop when 0.0.0.0/1 is added (rh #1203924) * Tue Mar 17 2015 Stef Walter - 1:0.9.10.2-3 - Fix dbus-glib dependency * Mon Mar 16 2015 Dan Williams - 1:0.9.10.2-2 - Turn off keepalive for connectivity checking * Wed Mar 4 2015 Dan Williams - 1:0.9.10.2-1 - Update to 0.9.10.2 release * Thu Feb 19 2015 Dan Williams - 1:0.9.10.1-3 - Update to 0.9.10.2 pre-release snapshot * Fri Jan 23 2015 Lubomir Rintel - 1:0.9.10.1-2 - Update to 0.9.10.1, a 0.9.10.2 release candidate 1 tarball * Thu Jan 15 2015 Jiří Klimeš - 1:0.9.10.1-1.4.20150115git - connectivity: fix an connectivity check endless loop (bgo #742823) * Thu Jan 15 2015 Jiří Klimeš - 1:0.9.10.1-1.3.20150115git - update to latest snapshot of 0.9.10 - dhcp: fix connection failures due to stale dhclient lease (rh #1181477) * Fri Jan 9 2015 Jiří Klimeš - 1:0.9.10.1-1.2.20150109git - dhcp: fix killing wrong process ID on dhclient release (rh #1179913) * Mon Jan 5 2015 Jiří Klimeš - 1:0.9.10.1-1.git20150105 - update to latest snapshot of 0.9.10 - dhcp: fix dhclient abnormal exit due to SIGPIPE (bgo #735962) (rh #1178666) * Mon Nov 24 2014 Jiří Klimeš - 1:0.9.10.0-14.git20140704 - vpn: propagate daemon exec error correctly (bgo #739436) - core: do not assert when a device is enslaved externally (rh #1167345)

References

[ 1 ] Bug #1209902 - CVE-2015-2924 NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements https://bugzilla.redhat.com/show_bug.cgi?id=1209902

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update NetworkManager' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
Name : NetworkManager
Product : Fedora 21
Version : 0.9.10.2
Release : 5.fc21
URL : https://wiki.gnome.org/Apps
Summary : Network connection manager and user applications

Related News