Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in wicd
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in wicd
ID: FEDORA-2012-1077
Distribution: Fedora
Plattformen: Fedora 15
Datum: Fr, 17. Februar 2012, 09:07
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0813
Applikationen: wicd

Originalnachricht

Name        : wicd
Product : Fedora 15
Version : 1.7.0
Release : 11.fc15
URL : http://wicd.sourceforge.net/
Summary : Wireless and wired network connection manager
Description :
Wicd is designed to give the user as much control over behavior of network
connections as possible. Every network, both wired and wireless, has its
own profile with its own configuration options and connection behavior.
Wicd will try to automatically connect only to networks the user specifies
it should try, with a preference first to a wired network, then to wireless.

This package provides the architecture-dependent components of wicd.

-------------------------------------------------------------------------------
-
Update Information:

CVE-2012-0813

A sensitive information disclosure flaw was found in the way wicd, wireless and
wired network connection manager, performed management of sensitive information, to be stored in log files. Fields like 'password', 'identity', 'private_key', 'private_key_passwd' etc., were not excluded from being logged into /var/log/wicd log file, which could allow local attacker, with the privileges of the 'adm' group to view content of these entities in plain text, leading to information disclosure. This update fixes the problem.

A reboot is not technically necessary, but if you do not reboot your system
after installing this update, you should at least restart the wicd service.
-------------------------------------------------------------------------------
-
ChangeLog:

* Fri Jan 27 2012 David Cantrell <dcantrell@redhat.com> - 1.7.0-11
- Fix CVS-2012-0813 (#785147)
* Fri Aug 19 2011 David Cantrell <dcantrell@redhat.com> - 1.7.0-10
- Initialize appGui._wired_showing in __init__ (#723553)
- Make sure check and message in wicd-cli are a lambda (#712435)
* Thu Aug 11 2011 David Cantrell <dcantrell@redhat.com> - 1.7.0-9
- Correct systemd unit file for wicd, add D-Bus service file (#699116)
- Move docs to the wicd-common subpackage
- Correct /etc/dbus-1/system.d/wicd.conf (#699116)
* Mon May 9 2011 Bill Nottingham <notting@redhat.com> - 1.7.0-8
- fix systemd scriptlets for upgrade
* Mon Feb 7 2011 Fedora Release Engineering
<rel-eng@lists.fedoraproject.org>
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #785147 - CVE-2012-0813 wicd: Sensitive information disclosure via
log file entries
https://bugzilla.redhat.com/show_bug.cgi?id=785147
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update wicd' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung