Wicd before 1.7.1 saves sensitive information in log files in /var/log/wicd, which allows context-dependent attackers to obtain passwords and other sensitive information.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://launchpad.net/wicd/+announcement/9570 | |
http://www.openwall.com/lists/oss-security/2012/01/26/14 | mailing list |
http://www.securityfocus.com/bid/51703 | vdb entry |
http://secunia.com/advisories/49657 | third party advisory vendor advisory |
http://bazaar.launchpad.net/~wicd-devel/wicd/experimental/revision/682 | |
http://www.openwall.com/lists/oss-security/2012/01/26/13 | mailing list |
http://security.gentoo.org/glsa/glsa-201206-08.xml | vendor advisory |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=652417 |