LWN.net Logo

wicd: information disclosure

Package(s):wicd CVE #(s):CVE-2012-0813
Created:February 17, 2012 Updated:February 22, 2012
Description: From the Fedora advisory:

A sensitive information disclosure flaw was found in the way wicd, wireless and wired network connection manager, performed management of sensitive information, to be stored in log files. Fields like 'password', 'identity', 'private_key', 'private_key_passwd' etc., were not excluded from being logged into /var/log/wicd log file, which could allow local attacker, with the privileges of the 'adm' group to view content of these entities in plain text, leading to information disclosure.

Alerts:
Fedora FEDORA-2012-1059 2012-02-17
Fedora FEDORA-2012-1077 2012-02-17
Gentoo 201206-08 2012-06-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds