Vulnerability Name: | CVE-2012-0949 (CCN-75728) | ||||||||||||||||
Assigned: | 2012-05-17 | ||||||||||||||||
Published: | 2012-05-17 | ||||||||||||||||
Updated: | 2017-08-29 | ||||||||||||||||
Summary: | The Apport hook in Update Manager as used by Ubuntu 12.04 LTS, 11.10, and 11.04 uploads certain system state archive files when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a public bug report. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-0949 Source: OSVDB Type: UNKNOWN 82020 Source: CCN Type: SA49230 Ubuntu update for update-manager Source: SECUNIA Type: Vendor Advisory 49230 Source: CCN Type: OSVDB ID: 82020 Update Manager System State Archive File Uploading Weakness Repository Credential Remote Disclosure Source: BID Type: UNKNOWN 53605 Source: CCN Type: BID-53605 Ubuntu Update Manager CVE-2012-0949 Information Disclosure Vulnerability Source: UBUNTU Type: Vendor Advisory USN-1443-1 Source: XF Type: UNKNOWN update-manager-archives-info-disclosure(75728) Source: XF Type: UNKNOWN update-manager-archives-info-disclosure(75728) Source: CCN Type: USN-1443-1 Update Manager vulnerabilities | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |