Name | CVE-2016-0764 |
Description | Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 820354 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
network-manager (PTS) | jessie | 0.9.10.0-7 | vulnerable |
stretch | 1.6.2-3+deb9u2 | fixed | |
buster | 1.14.6-2+deb10u1 | fixed | |
bullseye | 1.30.6-1+deb11u1 | fixed | |
bookworm | 1.42.4-1 | fixed | |
sid, trixie | 1.50.0-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
network-manager | source | (unstable) | 1.1.91-1 | 820354 |
[jessie] - network-manager <no-dsa> (Minor issue)
[wheezy] - network-manager <no-dsa> (Minor issue)
Upstream fix: https://cgit.freedesktop.org/NetworkManager/NetworkManager/commit/?id=60b7ed3bdc3941a3b7c56824fba4b7291e79041f (1.2-beta2)
Fixed in 1.0.12 for the 1.0.x branch: https://cgit.freedesktop.org/NetworkManager/NetworkManager/tree/NEWS?h=1.0.12