Vulnerability Description
The fpm exporter in Revelation 0.4.13-2 and earlier encrypts the version number but not the password when exporting a file, which might allow local users to obtain sensitive information.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mikel Olasagasti | Revelation | <= 0.4.13-2 |
Related Weaknesses (CWE)
References
- http://als.regnet.cz/fpm2/feedback/2
- http://knoxin.blogspot.co.uk/2012/06/revelation-password-manager-considered.html
- http://als.regnet.cz/fpm2/feedback/2
- http://knoxin.blogspot.co.uk/2012/06/revelation-password-manager-considered.html
FAQ
What is CVE-2012-3818?
CVE-2012-3818 is a vulnerability with a CVSS score of 2.1 (LOW). The fpm exporter in Revelation 0.4.13-2 and earlier encrypts the version number but not the password when exporting a file, which might allow local users to obtain sensitive information.
How severe is CVE-2012-3818?
CVE-2012-3818 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-3818?
Check the references section above for vendor advisories and patch information. Affected products include: Mikel Olasagasti Revelation.