Candidate: CVE-2010-3902 PublicDate: 2010-10-14 05:58:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3902 Description: OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output posted to the public openconnect-devel mailing list. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_openconnect: upstream_openconnect: released (2.26) dapper_openconnect: DNE hardy_openconnect: DNE jaunty_openconnect: DNE karmic_openconnect: ignored (reached end-of-life) lucid_openconnect: ignored (reached end-of-life) maverick_openconnect: ignored (reached end-of-life) natty_openconnect: ignored (reached end-of-life) oneiric_openconnect: not-affected (3.02-1) precise_openconnect: not-affected (3.02-1) quantal_openconnect: not-affected (3.02-1) raring_openconnect: not-affected (3.02-1) saucy_openconnect: not-affected (3.02-1) devel_openconnect: not-affected (3.02-1)