KDE smbview Readable Command Line Password Argument
BID:6474
Info
KDE smbview Readable Command Line Password Argument
| Bugtraq ID: | 6474 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 23 2002 12:00AM |
| Updated: | Dec 23 2002 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Florian Weimer <[email protected]>. |
| Vulnerable: |
KDE KDE 3.0.5 KDE KDE 3.0.4 KDE KDE 3.0.3 KDE KDE 3.0.2 KDE KDE 3.0.1 KDE KDE 3.0 |
| Not Vulnerable: | |
Discussion
KDE smbview Readable Command Line Password Argument
It has been reported that smbview takes a password argument via the command line. This presents a security risk as information passed via the command line may be viewable by other local users. Exploiting this vulnerability may result in a malicious local user obtaining another user's password.
It has been reported that smbview takes a password argument via the command line. This presents a security risk as information passed via the command line may be viewable by other local users. Exploiting this vulnerability may result in a malicious local user obtaining another user's password.
Exploit / POC
KDE smbview Readable Command Line Password Argument
No exploit is required.
No exploit is required.
Solution / Fix
KDE smbview Readable Command Line Password Argument
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
KDE smbview Readable Command Line Password Argument
References:
References:
- Re: KDE Security Advisory: Multiple vulnerabilities in KDE (Florian Weimer
)