NetworkManager is a network link manager that attempts to keep a wired orwireless network connection active at all times.A missing network certificate verification flaw was found inNetworkManager. If a user created a WPA Enterprise or 802.1x wirelessnetwork connection that was verified using a Certificate Authority (CA)certificate, and then later removed that CA certificate file,NetworkManager failed to verify the identity of the network on thefollowing connection attempts. In these situations, a malicious wirelessnetwork spoofing the original network could trick a user into disclosingauthentication credentials or communicating over an untrusted network.(CVE-2009-4144)An information disclosure flaw was found in NetworkManager'snm-connection-editor D-Bus interface. If a user edited network connectionoptions using nm-connection-editor, a summary of those changes wasbroadcasted over the D-Bus message bus, possibly disclosing sensitiveinformation (such as wireless network authentication credentials) to otherlocal users. (CVE-2009-4145)Users of NetworkManager should upgrade to these updated packages, whichcontain backported patches to correct these issues.