CVE-2013-2120: High severity kde paste applet vulnerability
A security flaw was found in the way PasteMacroExpander of paste applet of kdeplasma-addons, a suite of additional plasmoids for KDE desktop environment, performed password generation / derivation for user provided string. An attacker could use this flaw to obtain plaintext form of such a password (possibly leading to their subsequent ability for unauthorized access to a service / resource, intended to be protected by such a password).
References: [1] http://www.openwall.com/lists/oss-security/2013/05/28/5 [2] https://bugzilla.novell.com/showbug.cgi?id=822595
Other sources
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2013-2120.
What is the severity of CVE-2013-2120?
The severity of CVE-2013-2120 is high with a CVSS score of 8.4.
What is the affected software?
The affected software is the KDE Paste Applet before version 4.10.5.
How does this vulnerability affect authentication?
This vulnerability allows context-dependent attackers to bypass authentication via a brute-force attack.
Are there any references for further information?
Yes, you can find more information at the following references: [Reference 1](http://archives.neohapsis.com/archives/bugtraq/2013-05/0114.html), [Reference 2](http://openwall.com/lists/oss-security/2013/05/28/5), [Reference 3](http://openwall.com/lists/oss-security/2013/05/29/6).