USN-3807-1: NetworkManager vulnerability
5 November 2018
NetworkManager could be made to crash or run programs if it received specially crafted network traffic.
- network-manager - Network connection manager
Felix Wilhelm discovered that the NetworkManager internal DHCPv6 client
incorrectly handled certain DHCPv6 messages. In non-default configurations
where the internal DHCP client is enabled, an attacker on the same network
could use this issue to cause NetworkManager to crash, resulting in a
denial of service, or possibly execute arbitrary code.
The problem can be corrected by updating your system to the following package versions:
After a standard system update you need to reboot your computer to make
all the necessary changes.
- USN-3806-1: libnss-resolve, libnss-systemd, systemd-journal-remote, libpam-systemd, systemd-sysv, udev-udeb, libudev1, systemd-container, systemd-coredump, libsystemd0, libnss-myhostname, libsystemd-dev, libnss-mymachines, systemd, systemd-tests, libudev-dev, libudev1-udeb, udev