com.canonical.NMOfono.ReadImsiContexts privilege escalation
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| network-manager (Ubuntu) |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
| Trusty |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
| Utopic |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
| Vivid |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Bug Description
Tavis Ormandy reports the following:
Apparently you're not happy with me for discussing local privilege
escalation on oss-security, so as you requested, here's what appears
to be a problem in Ubuntu-specific code.
I thought I'd take a quick look at D-Bus services you add in Ubuntu
after the usb-creator bug, this one jumps out at me as incorrect:
http://
_settings_
Untested, but that really looks like you can call
com.canonical.
and supply one of those glib keyfiles (i guess you just need to call
it "gprs")?
Tavis.
CVE References
| Changed in network-manager (Ubuntu Trusty): | |
| status: | New → Confirmed |
| Changed in network-manager (Ubuntu Utopic): | |
| status: | New → Confirmed |
| Changed in network-manager (Ubuntu Vivid): | |
| status: | New → Confirmed |
| Changed in network-manager (Ubuntu Trusty): | |
| assignee: | nobody → Marc Deslauriers (mdeslaur) |
| Changed in network-manager (Ubuntu Utopic): | |
| assignee: | nobody → Marc Deslauriers (mdeslaur) |
| Changed in network-manager (Ubuntu Vivid): | |
| assignee: | nobody → Marc Deslauriers (mdeslaur) |
| information type: | Private Security → Public Security |

This is CVE-2015-1322