First published: Sun Sep 11 2011(Updated: )
Description of problem: Between F14 and F15, NetworkManager was changed so that unprivileged console users can store both personal and system connections via the ifcfg-rh plugin. As a result, <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED WONTFIX - ifcfg plugin can write connection name containing newlines, corrupting file" href="show_bug.cgi?id=682290">bug 682290</a> now constitutes a vulnerability allowing such users to escalate to root. To avoid calling attention to this, I am filing a separate bug rather than updating <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED WONTFIX - ifcfg plugin can write connection name containing newlines, corrupting file" href="show_bug.cgi?id=682290">bug 682290</a>. Version-Release number of selected component (if applicable): NetworkManager-0.9.0-1.fc15 How reproducible: Always Steps to Reproduce (as an unprivileged console user): 1. Create a wired connection named `test'. 2. Change the name to `test\nUSERCTL=true\n/bin/bash', where `\n' stands for a newline entered via Ctrl-Shift-U, A. 3. usernetctl test up Actual results: Root shell. Expected results: Format integrity of /etc/sysconfig/network-scripts/ifcfg-test is maintained.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetworkManager | =0.8.1 | |
NetworkManager | =0.9.1 | |
NetworkManager | =0.9.0 | |
GNOME ifcfg-rh plug-in | ||
NetworkManager | =0.8.1 | |
NetworkManager | =0.9.0 | |
NetworkManager | =0.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3364 has a moderate severity rating due to the potential for local privilege escalation by unprivileged console users.
To fix CVE-2011-3364, update the NetworkManager and ifcfg-rh plugin to the latest versions that address this vulnerability.
CVE-2011-3364 affects GNOME's NetworkManager versions prior to 0.9.1 and the ifcfg-rh plugin in the specified configurations.
CVE-2011-3364 is classified as a local privilege escalation vulnerability in NetworkManager.
Any user with unprivileged access on systems running susceptible versions of NetworkManager and the ifcfg-rh plugin may be impacted by CVE-2011-3364.