First published: Tue Mar 10 2020(Updated: )
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME NetworkManager | <=0.9.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-1096 is medium with a CVSS score of 5.5.
CVE-2012-1096 allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection in NetworkManager 0.9 and earlier.
NetworkManager 0.9.0, GNOME NetworkManager, Debian Debian Linux 8.0, Debian Debian Linux 9.0, and Debian Debian Linux 10.0 are affected by CVE-2012-1096.
Upgrade NetworkManager to a version that is not affected by CVE-2012-1096 or apply the necessary patches provided by the vendor.
More information about CVE-2012-1096 can be found at the following references: [1] [2] [3].