Bug 137556 - netapplet allows unprivileged users to break routing tables
Summary: netapplet allows unprivileged users to break routing tables
Status: RESOLVED INVALID
Alias: None
Product: SUSE LINUX 10.0
Classification: openSUSE
Component: Security (show other bugs)
Version: Final
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-12-08 10:56 UTC by Stanislav Brabec
Modified: 2005-12-08 11:02 UTC (History)
1 user (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stanislav Brabec 2005-12-08 10:56:42 UTC
Netapplet is dropped for 10.1, but following behavior in 10.0 can have security implications (DoS):

1. Install a machine with default GNOME selection.
2. Configure your machine as a router (in my case wlan0 to eth0).
3. Log-in to GNOME as unprivileged users.
4. Click to netapplet eth0, then wlan0

Actual result:
eth0 (or wlan0) are down

Expected result:
Do not allow this behavior as default.

Additional notes:
Netapplet has no use on server, router, stationary desktop.
Bug 131117 can be related.
Comment 1 Thomas Biege 2005-12-08 11:02:50 UTC
that is true. but then don't install netapplet and neither gnome. :)