VYPR

rpm package

opensuse/NetworkManager&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/NetworkManager&distro=openSUSE%20Tumbleweed

Vulnerabilities (8)

  • CVE-2021-20297May 26, 2021
    affected < 1.32.10-2.1fixed 1.32.10-2.1

    A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.

  • CVE-2020-13529May 10, 2021
    affected < 1.32.10-2.1fixed 1.32.10-2.1

    An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigu

  • CVE-2020-10754Jun 8, 2020
    affected < 1.32.10-2.1fixed 1.32.10-2.1

    It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made i

  • CVE-2006-7246Jan 27, 2020
    affected < 1.4.2-1.2fixed 1.4.2-1.2

    NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.

  • CVE-2018-15688Oct 26, 2018
    affected < 1.32.10-2.1fixed 1.32.10-2.1

    A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.

  • CVE-2018-1000135Mar 20, 2018
    affected < 1.32.10-2.1fixed 1.32.10-2.1

    GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vulnerability appears to have been fixed in Some Ubuntu 16.04 p

  • CVE-2016-0764MedJul 17, 2017
    affected < 1.4.2-1.2fixed 1.4.2-1.2

    Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by r

  • CVE-2015-2924Nov 16, 2015
    affected < 1.4.2-1.2fixed 1.4.2-1.2

    The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar