{"id":"MGASA-2013-0262","summary":"Updated nagstamon package fixes security vulnerability","details":"A user details information exposure flaw was found in the way Nagstamon\nperformed automated requests to get information about available updates.\nRemote attackers could use this flaw to obtain user credentials for servers\nmonitored by the desktop status monitor due to their improper (base64\nencoding-based) encoding in the HTTP request, when the HTTP Basic\nauthentication scheme was used (CVE-2013-4114).\n","modified":"2026-04-16T06:25:40.139100292Z","published":"2013-08-30T17:19:33Z","upstream":["CVE-2013-4114"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2013-0262.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=10779"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2013-July/111698.html"}],"affected":[{"package":{"name":"nagstamon","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/nagstamon?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.9-1.2.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0262.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}