CVE-2013-4114

NameCVE-2013-4114
DescriptionThe automatic update request in Nagstamont before 0.9.10 uses a cleartext base64 format for transmission of a username and password, which allows remote attackers to obtain sensitive information by sniffing the network.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs716718

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nagstamon (PTS)buster3.2.1-1fixed
bullseye3.4.1-1fixed
bookworm3.10.1+ds1-6fixed
sid, trixie3.14.0+ds1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nagstamonsource(unstable)0.9.9-2low716718

Notes

[wheezy] - nagstamon <no-dsa> (Minor issue)
[squeeze] - nagstamon <no-dsa> (Minor issue)
update checks are disabled in Debian by default, see debian/patches/check-for-new-version.patch

Search for package or bug name: Reporting problems