From 539e8917835f7c7401a65a5c82b96ffed9c18e4e Mon Sep 17 00:00:00 2001 From: Thomas Deutschmann Date: Sat, 8 Jul 2017 14:16:07 +0200 Subject: Add GLSA 201707-09 --- glsa-201707-09.xml | 53 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 53 insertions(+) create mode 100644 glsa-201707-09.xml (limited to 'glsa-201707-09.xml') diff --git a/glsa-201707-09.xml b/glsa-201707-09.xml new file mode 100644 index 00000000..d8ac9db0 --- /dev/null +++ b/glsa-201707-09.xml @@ -0,0 +1,53 @@ + + + + GNOME applet for NetworkManager: Arbitrary file read/write + A vulnerability has been found in GNOME applet for NetworkManager + allowing local attackers to access the local filesystem. + + nm-applet + 2017-07-08 + 2017-07-08: 1 + 613768 + local + + + 1.4.6-r1 + 1.4.6-r1 + + + +

GNOME applet for NetworkManager is a GTK+ 3 front-end which works under + Xorg environments with a systray. +

+
+ +

Frederic Bardy and Quentin Biguenet discovered that GNOME applet for + NetworkManager incorrectly checked permissions when connecting to certain + wireless networks. +

+
+ +

A local attacker could bypass security restrictions at the login screen + to access local files. +

+
+ +

There is no known workaround at this time.

+
+ +

All GNOME applet for NetworkManager users should upgrade to the latest + version: +

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=gnome-extra/nm-applet-1.4.6-r1" + +
+ + CVE-2017-6590 + + BlueKnight + whissi +
-- cgit v1.2.3-65-gdbad