Vulnerabilities > CVE-2012-0813 - Credentials Management vulnerability in David Paleino Wicd

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
david-paleino
CWE-255
nessus

Summary

Wicd before 1.7.1 saves sensitive information in log files in /var/log/wicd, which allows context-dependent attackers to obtain passwords and other sensitive information.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2012-1077.NASL
    description - CVE-2012-0813 A sensitive information disclosure flaw was found in the way wicd, wireless and wired network connection manager, performed management of sensitive information, to be stored in log files. Fields like
    last seen2020-03-17
    modified2012-02-17
    plugin id57987
    published2012-02-17
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/57987
    titleFedora 15 : wicd-1.7.0-11.fc15 (2012-1077)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-201206-08.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-201206-08 (Wicd: Multiple vulnerabilities) Two vulnerabilities have been found in Wicd: Passwords and passphrases are written to /var/log/wicd (CVE-2012-0813). Input from the daemon
    last seen2020-06-01
    modified2020-06-02
    plugin id59646
    published2012-06-22
    reporterThis script is Copyright (C) 2012-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/59646
    titleGLSA-201206-08 : Wicd: Multiple vulnerabilities
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2012-1059.NASL
    description - CVE-2012-0813 A sensitive information disclosure flaw was found in the way wicd, wireless and wired network connection manager, performed management of sensitive information, to be stored in log files. Fields like
    last seen2020-03-17
    modified2012-02-17
    plugin id57986
    published2012-02-17
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/57986
    titleFedora 16 : wicd-1.7.0-10.fc16 (2012-1059)