CVE-2011-1943

The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
gnomenetworkmanager
𝑥
< 0.8.9997
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
network-manager-openvpn
bullseye
1.8.12-2
fixed
bookworm
1.10.2-2
fixed
sid
1.12.0-2
fixed
trixie
1.12.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
network-manager
vivid
not-affected
utopic
not-affected
trusty
dne
precise
not-affected
network-manager-openvpn
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
not-affected
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
ignored