Bug 137556

Summary: netapplet allows unprivileged users to break routing tables
Product: [openSUSE] SUSE LINUX 10.0 Reporter: Stanislav Brabec <sbrabec>
Component: SecurityAssignee: Security Team bot <security-team>
Status: RESOLVED INVALID QA Contact: E-mail List <qa-bugs>
Severity: Normal    
Priority: P5 - None CC: clahey
Version: Final   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: Other Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Stanislav Brabec 2005-12-08 10:56:42 UTC
Netapplet is dropped for 10.1, but following behavior in 10.0 can have security implications (DoS):

1. Install a machine with default GNOME selection.
2. Configure your machine as a router (in my case wlan0 to eth0).
3. Log-in to GNOME as unprivileged users.
4. Click to netapplet eth0, then wlan0

Actual result:
eth0 (or wlan0) are down

Expected result:
Do not allow this behavior as default.

Additional notes:
Netapplet has no use on server, router, stationary desktop.
Bug 131117 can be related.
Comment 1 Thomas Biege 2005-12-08 11:02:50 UTC
that is true. but then don't install netapplet and neither gnome. :)