Candidate: CVE-2012-3818 PublicDate: 2012-06-29 17:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3818 http://knoxin.blogspot.co.uk/2012/06/revelation-password-manager-considered.html http://als.regnet.cz/fpm2/feedback/2 Description: The fpm exporter in Revelation 0.4.13-2 and earlier encrypts the version number but not the password when exporting a file, which might allow local users to obtain sensitive information. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=680059 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-3818 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_revelation: upstream_revelation: needs-triage hardy_revelation: ignored (reached end-of-life) lucid_revelation: ignored (reached end-of-life) natty_revelation: ignored (reached end-of-life) oneiric_revelation: ignored (reached end-of-life) precise_revelation: ignored (reached end-of-life) precise/esm_revelation: DNE (precise was needed) quantal_revelation: ignored (reached end-of-life) raring_revelation: ignored (reached end-of-life) saucy_revelation: ignored (reached end-of-life) trusty_revelation: not-affected (0.4.14-2) trusty/esm_revelation: DNE (trusty was not-affected [0.4.14-2]) utopic_revelation: not-affected (0.4.14-2) vivid_revelation: not-affected (0.4.14-2) vivid/stable-phone-overlay_revelation: DNE vivid/ubuntu-core_revelation: DNE wily_revelation: not-affected (0.4.14-2) xenial_revelation: not-affected (0.4.14-2) yakkety_revelation: not-affected (0.4.14-2) zesty_revelation: not-affected (0.4.14-2) devel_revelation: not-affected (0.4.14-2)