CVE-2004-1171
Summary
| CVE | CVE-2004-1171 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-01-10 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares. |
Risk And Classification
Primary CVSS: v2.0 2.1 from [email protected]
AV:L/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Kde | Kde | 3.2 | All | All | All |
| Operating System | Kde | Kde | 3.2.1 | All | All | All |
| Operating System | Kde | Kde | 3.2.2 | All | All | All |
| Operating System | Kde | Kde | 3.2.3 | All | All | All |
| Operating System | Kde | Kde | 3.3 | All | All | All |
| Operating System | Kde | Kde | 3.3.1 | All | All | All |
| Operating System | Kde | Kde | 3.3.2 | All | All | All |
| Operating System | Mandrakesoft | Mandrake Linux | 10.0 | All | All | All |
| Operating System | Mandrakesoft | Mandrake Linux | 10.0 | All | amd64 | All |
| Operating System | Mandrakesoft | Mandrake Linux | 10.1 | All | All | All |
| Operating System | Mandrakesoft | Mandrake Linux | 10.1 | All | x86_64 | All |
| Operating System | Redhat | Fedora Core | core_2.0 | All | All | All |
| Operating System | Redhat | Fedora Core | core_3.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| archives.neohapsis.com/archives/fulldisclosure/2004-11/1292.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| P-051: SMB Password Disclosure | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | |
| 'Password Disclosure for SMB Shares in KDE's Konqueror' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Advisories - Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.kde.org/info/security/advisory-20041209-1.txt | af854a3a-2127-422b-91ae-364da2661108 | www.kde.org | |
| SecurityTracker.com Archives - KDE May Disclose SMB Passwords to Remote Users Via URLs | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| 'KDE Security Advisory: plain text password exposure' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Gentoo Linux Documentation -- kdelibs, kdebase: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| 404 - Page not found! - SEC Consult | af854a3a-2127-422b-91ae-364da2661108 | www.sec-consult.com | |
| Secunia - Advisories - Mandrake update for kdebase/kdelibs | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Secunia - Advisories - Fedora update for kdebase/kdelibs | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| KDE Plaintext Password Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| Secunia - Advisories - Gentoo update for kdelibs / kdebase | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| US-CERT Vulnerability Note VU#305294 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| www.osvdb.org/12248 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.