Candidate: CVE-2011-1943 PublicDate: 2011-06-14 17:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1943 Description: The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file. Ubuntu-Description: Notes: sbeattie> according to debian, affects network-manager, not sbeattie> network-manager-openvpn Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=628730 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_network-manager-openvpn: upstream: http://cgit.freedesktop.org/NetworkManager/NetworkManager/commit/?id=78ce088843d59d4494965bfc40b30a2e63d065f6 upstream_network-manager-openvpn: released hardy_network-manager-openvpn: ignored (reached end-of-life) lucid_network-manager-openvpn: ignored (reached end-of-life) maverick_network-manager-openvpn: ignored (reached end-of-life) natty_network-manager-openvpn: ignored (reached end-of-life) oneiric_network-manager-openvpn: ignored (reached end-of-life) precise_network-manager-openvpn: not-affected quantal_network-manager-openvpn: ignored (reached end-of-life) raring_network-manager-openvpn: ignored (reached end-of-life) saucy_network-manager-openvpn: ignored (reached end-of-life) trusty_network-manager-openvpn: not-affected trusty/esm_network-manager-openvpn: DNE (trusty was not-affected) utopic_network-manager-openvpn: not-affected vivid_network-manager-openvpn: not-affected devel_network-manager-openvpn: not-affected Patches_network-manager: upstream: http://cgit.freedesktop.org/NetworkManager/NetworkManager/commit/?id=78ce088843d59d4494965bfc40b30a2e63d065f6 upstream_network-manager: released precise_network-manager: not-affected (0.9.4.0-0ubuntu3) trusty_network-manager: not-affected (0.9.4.0-0ubuntu3) trusty/esm_network-manager: DNE (trusty was not-affected [0.9.4.0-0ubuntu3]) utopic_network-manager: not-affected (0.9.4.0-0ubuntu3) vivid_network-manager: not-affected (0.9.4.0-0ubuntu3) devel_network-manager: not-affected (0.9.4.0-0ubuntu3)