First published: Wed Apr 29 2015(Updated: )
Directory traversal vulnerability in the Ubuntu network-manager package for Ubuntu (vivid) before 0.9.10.0-4ubuntu15.1, Ubuntu 14.10 before 0.9.8.8-0ubuntu28.1, and Ubuntu 14.04 LTS before 0.9.8.8-0ubuntu7.1 allows local users to change the modem device configuration or read arbitrary files via a .. (dot dot) in the file name in a request to read modem device contexts (com.canonical.NMOfono.ReadImsiContexts).
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =14.04 | |
Ubuntu | =14.10 | |
Ubuntu | =15.1 | |
NetworkManager OpenVPN (Gnome) | <=0.9.8.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1322 has a moderate severity level, allowing local users to exploit the vulnerability.
To fix CVE-2015-1322, update the network-manager package to the latest version available for your Ubuntu system.
CVE-2015-1322 affects Ubuntu versions prior to 0.9.10.0-4ubuntu15.1 for vivid, 0.9.8.8-0ubuntu28.1 for 14.10, and 0.9.8.8-0ubuntu7.1 for 14.04 LTS.
CVE-2015-1322 is classified as a directory traversal vulnerability.
CVE-2015-1322 is a local vulnerability, meaning it requires local access to the system for exploitation.