5
CVSSv2

CVE-2013-4114

Published: 16/08/2013 Updated: 21/08/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The automatic update request in Nagstamont prior to 0.9.10 uses a cleartext base64 format for transmission of a username and password, which allows remote malicious users to obtain sensitive information by sniffing the network.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

henri wahl nagstamon

henri wahl nagstamon 0.8.0

henri wahl nagstamon 0.7.0

henri wahl nagstamon 0.6.2

henri wahl nagstamon 0.6.1

henri wahl nagstamon 0.9.8

henri wahl nagstamon 0.9.7

henri wahl nagstamon 0.9.1

henri wahl nagstamon 0.8.2

henri wahl nagstamon 0.5.13

henri wahl nagstamon 0.5.10

henri wahl nagstamon 0.5.5

henri wahl nagstamon 0.5.3

henri wahl nagstamon 0.9.6

henri wahl nagstamon 0.9.5

henri wahl nagstamon 0.9.4

henri wahl nagstamon 0.9.3

henri wahl nagstamon 0.9.2

henri wahl nagstamon 0.5.9

henri wahl nagstamon 0.5.8

henri wahl nagstamon 0.5.7

henri wahl nagstamon 0.5.6

henri wahl nagstamon 0.9.7.1

henri wahl nagstamon 0.9.6.1

henri wahl nagstamon 0.9.0

henri wahl nagstamon 0.8.1

henri wahl nagstamon 0.6

henri wahl nagstamon 0.5.11

henri wahl nagstamon 0.5.4

henri wahl nagstamon 0.5.2

Vendor Advisories

Debian Bug report logs - #716718 nagstamon: CVE-2013-4114: credentials exposure Package: nagstamon; Maintainer for nagstamon is Python Applications Packaging Team <python-apps-team@listsaliothdebianorg>; Source for nagstamon is src:nagstamon (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Thu, ...
Debian Bug report logs - #716718 nagstamon: CVE-2013-4114: credentials exposure Package: nagstamon; Maintainer for nagstamon is Python Applications Packaging Team <python-apps-team@listsaliothdebianorg>; Source for nagstamon is src:nagstamon (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Thu, ...
Debian Bug report logs - #716718 nagstamon: CVE-2013-4114: credentials exposure Package: nagstamon; Maintainer for nagstamon is Python Applications Packaging Team <python-apps-team@listsaliothdebianorg>; Source for nagstamon is src:nagstamon (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Thu, ...