USN-3807-1: NetworkManager vulnerability
5 November 2018
NetworkManager could be made to crash or run programs if it received specially crafted network traffic.
- network-manager - Network connection manager
Felix Wilhelm discovered that the NetworkManager internal DHCPv6 client
incorrectly handled certain DHCPv6 messages. In non-default configurations
where the internal DHCP client is enabled, an attacker on the same network
could use this issue to cause NetworkManager to crash, resulting in a
denial of service, or possibly execute arbitrary code.
The problem can be corrected by updating your system to the following package versions:
After a standard system update you need to reboot your computer to make
all the necessary changes.
- USN-3806-1: libudev1-udeb, systemd, libudev-dev, systemd-tests, libnss-mymachines, udev, libpam-systemd, libsystemd-dev, libnss-systemd, systemd-container, libnss-myhostname, systemd-coredump, systemd-sysv, udev-udeb, libnss-resolve, libudev1, systemd-journal-remote, libsystemd0