Release date:
Updated on: 2011-11-23
Affected Systems:
S. u. S.E. openSUSE 12.1
S. u. S.E. openSUSE 11.4
S. u. S.E. openSUSE 11.3
GNOME NetworkManager 0.8.9997
GNOME NetworkManager 0.8.990-3
GNOME NetworkManager 0.7.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50766
Cve id: CVE-2006-7246
GNOME NetworkManager is the network device and Connection Manager.
After GNOME NetworkManager is connected to some wireless networks, there is a security restriction bypass vulnerability in SSL certificate verification. Attackers can exploit this vulnerability to perform man-in-the-middle attacks and simulate it as a trusted website.
<* Source: unknown
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
GNOME
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.gnome.org/