Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Ubuntu 16.10: 3217-1 Critical: Network-Manager-Applet Local Attack

Ubuntu Large Esm H500
The system could be made to expose sensitive information.
=========================================================================Ubuntu Security Notice USN-3217-1
March 07, 2017

network-manager-applet vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

The system could be made to expose sensitive information.

Software Description:
- network-manager-applet: GNOME frontend for NetworkManager

Details:

It was discovered that network-manager-applet incorrectly checked
permissions when connecting to certain wireless networks. A local attacker
could use this issue at the login screen to access local files.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
  network-manager-gnome           1.2.6-0ubuntu1.1

Ubuntu 16.04 LTS:
  network-manager-gnome           1.2.6-0ubuntu0.16.04.2

Ubuntu 14.04 LTS:
  network-manager-gnome           0.9.8.8-0ubuntu4.5

Ubuntu 12.04 LTS:
  network-manager-gnome           0.9.4.1-0ubuntu2.6

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3217-1
  https://bugs.launchpad.net/ubuntu/+source/network-manager-applet/+bug/1668321

Package Information:
  https://launchpad.net/ubuntu/+source/network-manager-applet/1.2.6-0ubuntu1.1
  https://launchpad.net/ubuntu/+source/network-manager-applet/1.2.6-0ubuntu0.16.04.2
  https://launchpad.net/ubuntu/+source/network-manager-applet/0.9.8.8-0ubuntu4.5
  https://launchpad.net/ubuntu/+source/network-manager-applet/0.9.4.1-0ubuntu2.6


Ubuntu 16.10: 3217-1 Critical: Network-Manager-Applet Local Attack

ubuntu
Calendar Grey March 7, 2017
Dist Ubuntu Esm H88
The vulnerability discovered in Ubuntu's network-manager-applet may result in potential exposure of private data. Ensure your system is updated without delay.
The system could be made to expose sensitive information.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: network-manager-gnome 1.2.6-0ubuntu1.1 Ubuntu 16.04 LTS: network-manager-gnome 1.2.6-0ubuntu0.16.04.2 Ubuntu 14.04 LTS: network-manager-gnome 0.9.8.8-0ubuntu4.5 Ubuntu 12.04 LTS: network-manager-gnome 0.9.4.1-0ubuntu2.6 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3217-1

https://bugs.launchpad.net/ubuntu/+source/network-manager-applet/+bug/1668321

Severity
critical
Lowest
Low
Medium
High
Critical

March 07, 2017

Package Information

https://launchpad.net/ubuntu/+source/network-manager-applet/1.2.6-0ubuntu1.1 https://launchpad.net/ubuntu/+source/network-manager-applet/1.2.6-0ubuntu0.16.04.2 https://launchpad.net/ubuntu/+source/network-manager-applet/0.9.8.8-0ubuntu4.5 https://launchpad.net/ubuntu/+source/network-manager-applet/0.9.4.1-0ubuntu2.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here