CVE-2013-2213: Medium severity kde paste applet vulnerability
Michael Samuel (mik) reports: KRandom::random() should not be considered a secure PRNG due to having a limited space of random values (32bits).
Reference: http://openwall.com/lists/oss-security/2013/06/26/1 http://openwall.com/lists/oss-security/2013/06/26/2
Other sources
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2013-2213.
What is the severity of CVE-2013-2213?
The severity of CVE-2013-2213 is medium with a CVSS score of 5.5.
Which software is affected by CVE-2013-2213?
The KDE Paste Applet after version 4.10.5 in kdeplasma-addons is affected by CVE-2013-2213.
How does the vulnerability in CVE-2013-2213 impact cryptographic protection mechanisms?
The vulnerability in CVE-2013-2213 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.
Is there a fix available for CVE-2013-2213?
Yes, updating to a version of KDE Paste Applet after 4.10.5 in kdeplasma-addons will fix the vulnerability CVE-2013-2213.