SUSE-SU-2016:1465-1

    Dashboard / Vulnerabilities / SUSE-SU-2016:1465-1

    SUSE-SU-2016:1465-1

    Published: 1 Jun 2016Last Modified: 1 Jun 2016

    Summary: Recommended update for NetworkManager-kde4

    Details: This NetworkManager-kde4 update fixes the following security and non security issues: - Fixed a long standing security issue. This makes knetworkmanager probe the RADIUS server for a CA certificate subject and hash if no CA certificate is specified. knetworkmanager then stores this data and send it to NetworkManager for it to do a network validation in the absence of a real certificate (bsc#726349) - Disabled the loading by default of the NetworkManager plasma applet since it doesn't work. - Fixed a crash due to the use of an uninitialized variable in the plasma applet in case someone runs it manually (bsc#663413)

    Affected packages

    Package

    Name: NetworkManager-kde4

    Purl: pkg:rpm/suse/NetworkManager-kde4&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.9.svn1043876-1.3.15

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2016:1465-1 | CVE-DB