CVE-2009-4145

nm-connection-editor <0.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54898
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10539
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37580
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/12/16/3
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37819
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0108.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38420

Scores

EPSS 0.0006
EPSS Percentile 19.2%

Details

CWE
CWE-200
Status published
Products (1)
gnome/networkmanager 0.7.2
Published Dec 23, 2009
Tracked Since Feb 18, 2026