CVE-2020-10754

Priority
Description
It was found that nmcli, a command line interface to NetworkManager did not
honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a
new profile. When a user connects to a network using this profile, the
authentication does not happen and the connection is made insecurely.
Notes
mdeslauronly affects the ifcfg-rh settings plugin which isn't used on
Ubuntu, marking as not-affected
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):not-affected
Ubuntu 18.04 LTS (Bionic Beaver):not-affected
Ubuntu 20.04 LTS (Focal Fossa):not-affected
Ubuntu 20.10 (Groovy Gorilla):not-affected
Patches:
Upstream:https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/8affcc19b61fc3c516474ba075e61b82030feeb4
More Information

Updated: 2020-09-10 06:35:24 UTC (commit 81a23a978c4436cd99e1d040e9e73e9146876281)