Vulnerability Name: | CVE-2011-1943 (CCN-68057) | ||||||||||||
Assigned: | 2011-06-03 | ||||||||||||
Published: | 2011-06-03 | ||||||||||||
Updated: | 2021-11-02 | ||||||||||||
Summary: | The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file. | ||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-532 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: CONFIRM Type: Patch, Third Party Advisory http://cgit.freedesktop.org/NetworkManager/NetworkManager/commit/?id=78ce088843d59d4494965bfc40b30a2e63d065f6 Source: MITRE Type: CNA CVE-2011-1943 Source: FEDORA Type: Third Party Advisory FEDORA-2011-7919 Source: CCN Type: NetworkManager Web page NetworkManager - Linux Networking made Easy Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20110531 CVE request: NetworkManager-openvpn logs cert password Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20110531 Re: CVE request: NetworkManager-openvpn logs cert password Source: CCN Type: OSVDB ID: 73599 NetworkManager libnm-util nm-setting-vpn.c destroy_one_secret Function Log File Certificate Password Local Disclosure Source: CCN Type: Red Hat Bugzilla Bug 708876 CVE-2011-1943 NetworkManager: Password to unlock the certificate is being logged Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=708876 Source: XF Type: Third Party Advisory, VDB Entry networkmanager-secret-info-disclosure(68057) Source: XF Type: UNKNOWN networkmanager-secret-info-disclosure(68057) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |