CVE-2009-0365

nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:S/C:C/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
ubuntuubuntu_linux
6.06
ubuntuubuntu_linux
7.10
ubuntuubuntu_linux
8.04
ubuntuubuntu_linux
8.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
network-manager
bullseye
1.30.6-1+deb11u1
fixed
bookworm
1.42.4-1
fixed
sid
1.50.0-1
fixed
trixie
1.50.0-1
fixed
network-manager-applet
bullseye
1.20.0-3
fixed
bookworm
1.30.0-2
fixed
sid
1.36.0-1
fixed
trixie
1.36.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
network-manager
intrepid
Fixed 0.7~~svn20081018t105859-0ubuntu1.8.10.2
released
hardy
not-affected
gutsy
not-affected
dapper
Fixed 0.6.2-0ubuntu7.1
released
network-manager-applet
intrepid
Fixed 0.7~~svn20081020t000444-0ubuntu1.8.10.2
released
hardy
Fixed 0.6.6-0ubuntu3.1
released
gutsy
Fixed 0.6.5-0ubuntu11~7.10.1
released
dapper
dne
Common Weakness Enumeration
References