Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-7252

Опубликовано: 18 янв. 2015
Источник: debian
EPSS Низкий

Описание

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kde-runtimefixed4:4.12.2-1package
kde-runtimeno-dsawheezypackage
kdebase-runtimeremovedpackage
kdebase-runtimeno-dsasqueezepackage

Примечания

  • http://gaganpreet.in/blog/2013/07/24/kwallet-security-analysis/

  • Upstream advisory: https://www.kde.org/info/security/advisory-20150109-1.txt

EPSS

Процентиль: 67%
0.00535
Низкий

Связанные уязвимости

ubuntu
около 11 лет назад

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.

redhat
больше 12 лет назад

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.

nvd
около 11 лет назад

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.

suse-cvrf
почти 11 лет назад

Security update for kdebase4-runtime

github
больше 3 лет назад

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.

EPSS

Процентиль: 67%
0.00535
Низкий