CVE-2009-4145 – NetworkManager: information disclosure by nm-connection-editor
https://notcve.org/view.php?id=CVE-2009-4145
nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network. nm-connection-editor en NetworkManager (NM) v0.7.x envía objetos de conexión por el D-Bus sobre acciones en el editor GUI de conexión, permitiendo a usuarios locales obtener información sensible al leer las señales D-Bus, como se ha demostrado usando dbus-monitor para descubrir la contraseña de la red WiFi. • http://git.gnome.org/browse/network-manager-applet/commit/?h=NETWORKMANAGER_APPLET_0_7&id=56d87fcb86acb5359558e0a2ee702cfc0c3391f2 http://git.gnome.org/browse/network-manager-applet/commit/?h=NETWORKMANAGER_APPLET_0_7&id=8627880e07c8345f69ed639325280c7f62a8f894 http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00000.html http://secunia.com/advisories/37819 http://secunia.com/advisories/38420 http://www.openwall.com/lists/oss-security/2009/12/16/3 http://www.redhat.com/support/errata/RHSA-2010 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •