KDE Plasma Paste Applet Local Password Generation Vulnerability
BID:60216
Info
KDE Plasma Paste Applet Local Password Generation Vulnerability
| Bugtraq ID: | 60216 |
| Class: | Design Error |
| CVE: |
CVE-2013-2120 |
| Remote: | No |
| Local: | Yes |
| Published: | May 28 2013 12:00AM |
| Updated: | Apr 13 2015 09:38PM |
| Credit: | Michael Samuel |
| Vulnerable: |
KDE Plasma Paste Applet 0 |
| Not Vulnerable: | |
Discussion
KDE Plasma Paste Applet Local Password Generation Vulnerability
Paste Applet for KDE Plasma is prone to a local insecure password generation vulnerability.
Local attacker can leverage this issue to guess generated passwords.
Paste Applet for KDE Plasma is prone to a local insecure password generation vulnerability.
Local attacker can leverage this issue to guess generated passwords.
Exploit / POC
KDE Plasma Paste Applet Local Password Generation Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
KDE Plasma Paste Applet Local Password Generation Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
KDE Plasma Paste Applet Local Password Generation Vulnerability
References:
References:
- KDE Homepage (KDE)
- KDE Paste Applet (seclists)
- KDE Plasma Desktop (KDE)
- (CVE-2013-2120) CVE-2013-2120 kdeplasma-addons: Weak passwords generated by Past (Redhat)