Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

CVE Kennung:CAN-2004-1171
Beschreibung:KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.
Test Kennungen: Nicht verfügbar
Querverweise: Common Vulnerability Exposure (CVE) ID: CVE-2004-1171
BugTraq ID: 11866
http://www.securityfocus.com/bid/11866
Bugtraq: 20041129 Password Disclosure for SMB Shares in KDE's Konqueror (Google Search)
http://marc.info/?l=bugtraq&m=110178786809694&w=2
Bugtraq: 20041209 KDE Security Advisory: plain text password exposure (Google Search)
http://marc.info/?l=bugtraq&m=110261063201488&w=2
CERT/CC vulnerability note: VU#305294
http://www.kb.cert.org/vuls/id/305294
Computer Incident Advisory Center Bulletin: P-051
http://www.ciac.org/ciac/bulletins/p-051.shtml
http://archives.neohapsis.com/archives/fulldisclosure/2004-11/1292.html
http://www.gentoo.org/security/en/glsa/glsa-200412-16.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:150
http://www.sec-consult.com/index.php?id=118
http://www.osvdb.org/12248
http://securitytracker.com/id?1012471
http://secunia.com/advisories/13477
http://secunia.com/advisories/13486
http://secunia.com/advisories/13560
XForce ISS Database: kde-smb-password-plaintext(18267)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18267




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.