Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for connman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0369-1 Rating: important References: #1210395 Cross-References: CVE-2023-28488 CVSS scores: CVE-2023-28488 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for connman fixes the following issues: Update to 1.42 * Fix issue with iwd and signal strength calculation. * Fix issue with iwd and handling service removal. * Fix issue with iwd and handling new connections. * Fix issue with handling default online check URL. * Fix issue with handling nameservers refresh. * Fix issue with handling proxy from DHCP lease. (boo#1210395 CVE-2023-28488) * Fix issue with handling multiple proxies from PAC. * Fix issue with handling manual time update changes. * Fix issue with handling invalid gateway routes. * Fix issue with handling hidden WiFi agent requests. * Fix issue with handling WiFi SAE authentication failure. * Fix issue with handling DNS Proxy and TCP server replies. * Add support for regulatory domain following timezone. * Add support for localtime configuration option. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-369=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): connman-1.42-bp155.4.3.1 connman-client-1.42-bp155.4.3.1 connman-devel-1.42-bp155.4.3.1 connman-doc-1.42-bp155.4.3.1 connman-nmcompat-1.42-bp155.4.3.1 connman-plugin-iospm-1.42-bp155.4.3.1 connman-plugin-l2tp-1.42-bp155.4.3.1 connman-plugin-openvpn-1.42-bp155.4.3.1 connman-plugin-polkit-1.42-bp155.4.3.1 connman-plugin-pptp-1.42-bp155.4.3.1 connman-plugin-wireguard-1.42-bp155.4.3.1 connman-test-1.42-bp155.4.3.1 - openSUSE Backports SLE-15-SP5 (aarch64 ppc64le s390x x86_64): connman-plugin-vpnc-1.42-bp155.4.3.1 - openSUSE Backports SLE-15-SP5 (aarch64 i586 s390x x86_64): connman-plugin-hh2serial-gps-1.42-bp155.4.3.1 connman-plugin-tist-1.42-bp155.4.3.1 References: https://www.suse.com/security/cve/CVE-2023-28488.html https://bugzilla.suse.com/1210395 . This patch targets a significant flaw within connman on openSUSE, successfully rectifying security vulnerabilities and fortifying protection.. openSUSE Update, Connman Security, Important Fix, SLE-15-SP5, Security Patch. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in ConnMan, the worst of which can lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202310-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: ConnMan: Multiple Vulnerabilities Date: October 31, 2023 Bugs: #832028, #863425 ID: 202310-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in ConnMan, the worst of which can lead to remote code execution. Background ========== ConnMan provides a daemon for managing Internet connections. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------------ ------------------- net-misc/connman < 1.42_pre20220801 > = 1.42_pre20220801 Description =========== Multiple vulnerabilities have been discovered in ConnMan. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All ConnMan users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/connman-1.42_pre20220801" References ========== [ 1 ] CVE-2022-23096 https://nvd.nist.gov/vuln/detail/CVE-2022-23096 [ 2 ] CVE-2022-23097 https://nvd.nist.gov/vuln/detail/CVE-2022-23097 [ 3 ] CVE-2022-23098 https://nvd.nist.gov/vuln/detail/CVE-2022-23098 [ 4 ] CVE-2022-32292 https://nvd.nist.gov/vuln/detail/CVE-2022-32292 [ 5 ] CVE-2022-32293 https://nvd.nist.gov/vuln/detail/CVE-2022-32293 Availability ============ This GLSA and any updates to it are availablefor viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202310-21 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
It was discovered that there was a potential buffer overflow and denial of service vulnerabilty in the gdhcp client implementation of connman, a command-line network manager designed for use on embedded devices. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5416-1
It was discovered that there was a potential denial of service vulnerabilty in connman, a command-line network manager designed for use on embedded devices. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3397-1
Several vulnerabilities were discovered in ConnMan, a network manager for embedded devices, which could result in denial of service or the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3144-1
An update that fixes two vulnerabilities is now available. . openSUSE Security Update: Security update for connman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10134-1 Rating: critical References: #1200189 #1200190 Cross-References: CVE-2022-32292 CVE-2022-32293 CVSS scores: CVE-2022-32292 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-32293 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for connman fixes the following issues: - CVE-2022-32292: Add refcounting to wispr portal detection to avoid heap overflow (boo#1200190) - CVE-2022-32292: Fix OOB write in received_data (boo#1200189) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10134=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): connman-1.41-bp153.2.6.1 connman-client-1.41-bp153.2.6.1 connman-devel-1.41-bp153.2.6.1 connman-doc-1.41-bp153.2.6.1 connman-nmcompat-1.41-bp153.2.6.1 connman-plugin-iospm-1.41-bp153.2.6.1 connman-plugin-l2tp-1.41-bp153.2.6.1 connman-plugin-openvpn-1.41-bp153.2.6.1 connman-plugin-polkit-1.41-bp153.2.6.1 connman-plugin-pptp-1.41-bp153.2.6.1 connman-plugin-wireguard-1.41-bp153.2.6.1 connman-test-1.41-bp153.2.6.1 - openSUSE Backports SLE-15-SP3 (aarch64 ppc64le s390x x86_64): connman-plugin-vpnc-1.41-bp153.2.6.1 - openSUSE BackportsSLE-15-SP3 (aarch64 i586 s390x x86_64): connman-plugin-hh2serial-gps-1.41-bp153.2.6.1 connman-plugin-tist-1.41-bp153.2.6.1 References: https://www.suse.com/security/cve/CVE-2022-32292.html https://www.suse.com/security/cve/CVE-2022-32293.html https://bugzilla.suse.com/1200189 https://bugzilla.suse.com/1200190 . OpenSUSE has issued a crucial security alert concerning connman, highlighting serious vulnerabilities such as heap overflow and out-of-bounds write operations.. connman security update, openSUSE critical advisory, software patch connman. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities were discovered in ConnMan, a network manager for embedded devices, which could result in denial of service or the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5231-1
It was discovered that there were two issues in connman, a daemon for managing internet connections within embedded devices: * CVE-2022-32292: Prevent an issue where remote attackers able to . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3105-1
Get the latest Linux and open source security news straight to your inbox.