CVE-2009-4145
EPSS 0.06%
Description
nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.
How to fix CVE-2009-4145
To remediate CVE-2009-4145, upgrade the affected package to a fixed version below.
- Debian/network-manager-applet—upgrade to 0.7.2-2 or later
Is CVE-2009-4145 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.7.2-2