First published: Tue Apr 05 2016(Updated: )
A race condition that could disclose connection secrets to authenticated local users when changing ifcfg and keyfile connections was found. External Reference: <a href="https://mail.gnome.org/archives/networkmanager-list/2016-April/msg00000.html">https://mail.gnome.org/archives/networkmanager-list/2016-April/msg00000.html</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/NetworkManager | <1.0.12 | 1.0.12 |
Red Hat NetworkManager | <=1.0.8 | |
redhat enterprise Linux desktop | =7.0 | |
Red Hat Enterprise Linux HPC Node | =7.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0764 is classified as a medium severity vulnerability.
To fix CVE-2016-0764, update NetworkManager to version 1.0.12 or later.
CVE-2016-0764 affects users of NetworkManager versions less than 1.0.12 and specific Red Hat Enterprise Linux distributions.
CVE-2016-0764 is a race condition that can disclose connection secrets to authenticated local users.
No, CVE-2016-0764 requires local access, as it can only be exploited by authenticated local users.