CVE-2009-4145

NameCVE-2009-4145
Descriptionnm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs563371

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
network-manager (PTS)buster1.14.6-2+deb10u1fixed
bullseye1.30.6-1+deb11u1fixed
bookworm1.42.4-1fixed
sid, trixie1.46.0-1fixed
network-manager-applet (PTS)buster1.8.20-1.1fixed
bullseye1.20.0-3fixed
bookworm1.30.0-2fixed
trixie1.34.0-2fixed
sid1.36.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
network-managersource(unstable)(not affected)
network-manager-appletsourcelenny(not affected)
network-manager-appletsource(unstable)0.7.2-2low563371

Notes

- network-manager <not-affected> (-editor introduced in 0.7 on the -applet package)
[lenny] - network-manager-applet <not-affected> (-editor was introduced in 0.7)

Search for package or bug name: Reporting problems