~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-8296

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2017-8296
2
 
PublicDate: 2017-04-27
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8296
5
 
 http://www.openwall.com/lists/oss-security/2017/04/25/9
6
 
Description:
7
 
 kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is
8
 
 written in cleartext. All of the commands performed in the password manager
9
 
 are written there. This can lead to the disclosure of the master password
10
 
 if the "password" command is used with an argument. The names of the
11
 
 password entries created and consulted are also accessible in cleartext.
12
 
Ubuntu-Description:
13
 
Notes:
14
 
Bugs:
15
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860817
16
 
Priority: medium
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_kedpm:
21
 
upstream_kedpm: needs-triage
22
 
precise_kedpm: ignored (reached end-of-life)
23
 
precise/esm_kedpm: DNE (precise was needed)
24
 
trusty_kedpm: needed
25
 
vivid/stable-phone-overlay_kedpm: DNE
26
 
vivid/ubuntu-core_kedpm: DNE
27
 
xenial_kedpm: needed
28
 
yakkety_kedpm: ignored (reached end-of-life)
29
 
zesty_kedpm: ignored (reached end-of-life)
30
 
artful_kedpm: DNE
31
 
bionic_kedpm: DNE
32
 
devel_kedpm: DNE