Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-4003

Опубликовано: 06 окт. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-4003: NetworkManager security and bug fix update (MODERATE)

[1:1.18.8-1]

  • Update to 1.18.8 relase
  • ifcfg-rh: handle '802-1x.{,phase2-}ca-path' (rh #1841397, CVE-2020-10754)
  • ifcfg-rh: handle 802-1x.pin properties.

[1:1.18.6-4]

  • ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)

[1:1.18.6-3]

  • Update translations (rh #1796852)

[1:1.18.6-2]

  • vpn: gracefully handle invalid routes from VPN plugins
  • workaround g_strtoll() failing with EAGAIN (rh #1797915)

[1:1.18.6-1]

  • Update to 1.18.6 release
  • cli: unset 'ipv[46].never-default' when setting 'ipv[46].gateway' (rh #1785039)
  • core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
  • core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

NetworkManager

1.18.8-1.el7

NetworkManager-adsl

1.18.8-1.el7

NetworkManager-bluetooth

1.18.8-1.el7

NetworkManager-config-server

1.18.8-1.el7

NetworkManager-dispatcher-routing-rules

1.18.8-1.el7

NetworkManager-glib

1.18.8-1.el7

NetworkManager-glib-devel

1.18.8-1.el7

NetworkManager-libnm

1.18.8-1.el7

NetworkManager-libnm-devel

1.18.8-1.el7

NetworkManager-ovs

1.18.8-1.el7

NetworkManager-ppp

1.18.8-1.el7

NetworkManager-team

1.18.8-1.el7

NetworkManager-tui

1.18.8-1.el7

NetworkManager-wifi

1.18.8-1.el7

NetworkManager-wwan

1.18.8-1.el7

Oracle Linux x86_64

NetworkManager

1.18.8-1.el7

NetworkManager-adsl

1.18.8-1.el7

NetworkManager-bluetooth

1.18.8-1.el7

NetworkManager-config-server

1.18.8-1.el7

NetworkManager-dispatcher-routing-rules

1.18.8-1.el7

NetworkManager-glib

1.18.8-1.el7

NetworkManager-glib-devel

1.18.8-1.el7

NetworkManager-libnm

1.18.8-1.el7

NetworkManager-libnm-devel

1.18.8-1.el7

NetworkManager-ovs

1.18.8-1.el7

NetworkManager-ppp

1.18.8-1.el7

NetworkManager-team

1.18.8-1.el7

NetworkManager-tui

1.18.8-1.el7

NetworkManager-wifi

1.18.8-1.el7

NetworkManager-wwan

1.18.8-1.el7

Связанные CVE

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 5 лет назад

It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.

CVSS3: 4.3
redhat
больше 5 лет назад

It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.

CVSS3: 4.3
nvd
больше 5 лет назад

It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.

CVSS3: 4.3
debian
больше 5 лет назад

It was found that nmcli, a command line interface to NetworkManager di ...

github
больше 3 лет назад

It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.