2.1

CVE-2004-1171

KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kde ≫ Kde Version 3.2
Kde ≫ Kde Version 3.2.1
Kde ≫ Kde Version 3.2.2
Kde ≫ Kde Version 3.2.3
Kde ≫ Kde Version 3.3
Kde ≫ Kde Version 3.3.1
Kde ≫ Kde Version 3.3.2
Mandrakesoft ≫ Mandrake Linux Version 10.0
Mandrakesoft ≫ Mandrake Linux Version 10.0 Edition amd64
Mandrakesoft ≫ Mandrake Linux Version 10.1
Mandrakesoft ≫ Mandrake Linux Version 10.1 Edition x86_64
Redhat ≫ Fedora Core Version core_2.0
Redhat ≫ Fedora Core Version core_3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.357
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/13477
http://secunia.com/advisories/13486
http://secunia.com/advisories/13560
http://archives.neohapsis.com/archives/fulldisclosure/2004-11/1292.html
http://marc.info/?l=bugtraq&m=110178786809694&w=2
http://marc.info/?l=bugtraq&m=110261063201488&w=2
http://securitytracker.com/id?1012471
http://www.ciac.org/ciac/bulletins/p-051.shtml
http://www.gentoo.org/security/en/glsa/glsa-200412-16.xml
http://www.kb.cert.org/vuls/id/305294
Third Party Advisory
US Government Resource
http://www.kde.org/info/security/advisory-20041209-1.txt
http://www.mandriva.com/security/advisories?name=MDKSA-2004:150
http://www.osvdb.org/12248
http://www.sec-consult.com/index.php?id=118
http://www.securityfocus.com/bid/11866
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/18267