Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.871693
Categoría:Red Hat Local Security Checks
Título:RedHat Update for NetworkManager RHSA-2016:2581-02
Resumen:The remote host is missing an update for the 'NetworkManager'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'NetworkManager'
package(s) announced via the referenced advisory.

Vulnerability Insight:
NetworkManager is a system network service
that manages network devices and connections, attempting to keep active network
connectivity when available. Its capabilities include managing Ethernet, wireless,
mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration
with a variety of different VPN services.

The following packages have been upgraded to a newer upstream version:
NetworkManager (1.4.0), NetworkManager-libreswan (1.2.4),
network-manager-applet (1.4.0), libnl3 (3.2.28). (BZ#1264552, BZ#1296058,
BZ#1032717, BZ#1271581)

Security Fix(es):

* A race condition vulnerability was discovered in NetworkManager.
Temporary files were created insecurely when saving or updating connection
settings, which could allow local users to read connection secrets such as
VPN passwords or WiFi keys. (CVE-2016-0764)

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 7.3 Release Notes linked from the References section.

Affected Software/OS:
NetworkManager on Red Hat Enterprise Linux Server (v. 7)

Solution:
Please Install the Updated Packages.

CVSS Score:
2.1

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-0764
RedHat Security Advisories: RHSA-2016:2581
http://rhn.redhat.com/errata/RHSA-2016-2581.html
CopyrightCopyright (C) 2016 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.