wicd writes sensitive information in log files (password, passphrase...)

Bug #992177 reported by Julian Taylor
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
wicd (Debian)
Fix Released
Unknown
wicd (Ubuntu)
Fix Released
Undecided
Unassigned
Lucid
Fix Released
Undecided
Unassigned
Natty
Fix Released
Undecided
Unassigned
Oneiric
Fix Released
Undecided
Unassigned

Bug Description

Imported from Debian bug http://bugs.debian.org/652417:

Package: wicd
Version: 1.7.1~b3-3
Severity: grave
Tags: security
Justification: user security hole

wicd writes sensitive information in log files (under /var/log/wicd),
such as passwords and passphrases. Users in the adm group can have
access to them, but also log files are meant to be sent in bug
reports, and if the bug reporter doesn't pay attention, there is
a huge risk to transmit such information.

-- System Information:
Debian Release: wheezy/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (500, 'stable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 3.1.0-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=POSIX, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages wicd depends on:
ii wicd-daemon 1.7.1~b3-3
ii wicd-gtk [wicd-client] 1.7.1~b3-3

wicd recommends no packages.

wicd suggests no packages.

Versions of packages wicd-gtk depends on:
ii python 2.7.2-9
ii python-glade2 2.24.0-2
ii python-gtk2 2.24.0-2
ii wicd-daemon 1.7.1~b3-3

Versions of packages wicd-gtk recommends:
ii gksu 2.0.2-6
ii python-notify 0.1.1-3

Versions of packages wicd-daemon depends on:
ii adduser 3.113
ii dbus 1.4.16-1
ii debconf 1.5.41
ii ethtool 1:3.1-1
ii iproute 20111117-1
ii iputils-ping 3:20101006-1+b1
ii isc-dhcp-client [dhcp3-client] 4.1.1-P1-17
ii lsb-base 3.2-28
ii net-tools 1.60-24.1
ii psmisc 22.14-1
ii python 2.7.2-9
ii python-dbus 0.84.0-2
ii python-gobject 3.0.3-1
ii python-wicd 1.7.1~b3-3
ii wireless-tools 30~pre9-7
ii wpasupplicant 0.7.3-5

Versions of packages wicd-daemon recommends:
ii wicd-gtk [wicd-client] 1.7.1~b3-3

Versions of packages wicd-daemon suggests:
ii pm-utils 1.4.1-8

Versions of packages python-wicd depends on:
ii python 2.7.2-9
ii python2.6 2.6.7-4
ii python2.7 2.7.2-8

-- debconf information:
* wicd/users: vinc17
* wicd/users: vinc17

Related branches

CVE References

Julian Taylor (jtaylor)
Changed in wicd (Ubuntu):
status: New → Fix Released
Changed in wicd (Debian):
importance: Undecided → Unknown
status: New → Fix Released
Revision history for this message
Tyler Hicks (tyhicks) wrote :

jtaylor's branches look good. Packages are building and should be released soon.

Changed in wicd (Ubuntu Lucid):
status: New → Confirmed
Changed in wicd (Ubuntu Natty):
status: New → Confirmed
Changed in wicd (Ubuntu Oneiric):
status: New → Confirmed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package wicd - 1.7.0+ds1-6ubuntu0.11.10.1

---------------
wicd (1.7.0+ds1-6ubuntu0.11.10.1) oneiric-security; urgency=low

  * SECURITY UPDATE: local privilege escalation (LP: #979221)
    - debian/patches/36-fix_local_privilege_escalation.patch: sanitize
      config properties. Thanks to David Paleino <email address hidden>
    - CVE-2012-2095
  * SECURITY UPDATE: information leak in log files (LP: #992177)
    - debian/patches/37-mask-sensitive-info-from-log.patch: mask sensitive
      information in logs. Thanks to David Paleino <email address hidden>
    - CVE-2012-0813
 -- Julian Taylor <email address hidden> Mon, 30 Apr 2012 19:57:13 +0200

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package wicd - 1.7.0+ds1-6ubuntu0.11.04.1

---------------
wicd (1.7.0+ds1-6ubuntu0.11.04.1) natty-security; urgency=low

  * SECURITY UPDATE: local privilege escalation (LP: #979221)
    - debian/patches/36-fix_local_privilege_escalation.patch: sanitize
      config properties. Thanks to David Paleino <email address hidden>
    - CVE-2012-2095
  * SECURITY UPDATE: information leak in log files (LP: #992177)
    - debian/patches/37-mask-sensitive-info-from-log.patch: mask sensitive
      information in logs. Thanks to David Paleino <email address hidden>
    - CVE-2012-0813
 -- Julian Taylor <email address hidden> Mon, 30 Apr 2012 19:57:13 +0200

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package wicd - 1.7.0+ds1-2ubuntu0.1

---------------
wicd (1.7.0+ds1-2ubuntu0.1) lucid-security; urgency=low

  * SECURITY UPDATE: local privilege escalation (LP: #979221)
    - debian/patches/23-fix_local_privilege_escalation.patch: sanitize
      config properties. Thanks to David Paleino <email address hidden>
    - CVE-2012-2095
  * SECURITY UPDATE: information leak in log files (LP: #992177)
    - debian/patches/24-mask-sensitive-info-from-log.patch: mask sensitive
      information in logs. Thanks to David Paleino <email address hidden>
    - CVE-2012-0813
 -- Julian Taylor <email address hidden> Mon, 30 Apr 2012 22:15:04 +0200

Changed in wicd (Ubuntu Lucid):
status: Confirmed → Fix Released
Changed in wicd (Ubuntu Natty):
status: Confirmed → Fix Released
Changed in wicd (Ubuntu Oneiric):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.