kdesu Local Password Sniffing Vulnerability
BID:2320
Info
kdesu Local Password Sniffing Vulnerability
| Bugtraq ID: | 2320 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 23 2001 12:00AM |
| Updated: | Jan 23 2001 12:00AM |
| Credit: | Reported to bugtraq by Caldera Systems in a security advisory on January 23, 2001. |
| Vulnerable: |
KDE KDE 2.0 BETA KDE KDE 2.0 |
| Not Vulnerable: |
KDE KDE 1.2 KDE KDE 1.1.2 KDE KDE 1.1.1 KDE KDE 1.1 |
Discussion
kdesu Local Password Sniffing Vulnerability
kdesu permits a user to run a program as a different user by providing that user's password.
Versions of kdesu are vulnerable to a weak password protection scheme.
It is possible for a user on the system to intercept the password supplied at the command line.
This may lead to an elevation of privileges for the attacker.
kdesu permits a user to run a program as a different user by providing that user's password.
Versions of kdesu are vulnerable to a weak password protection scheme.
It is possible for a user on the system to intercept the password supplied at the command line.
This may lead to an elevation of privileges for the attacker.
References
kdesu Local Password Sniffing Vulnerability
References:
References: