4.6
CVSSv2

CVE-2006-2442

Published: 18/05/2006 Updated: 08/03/2011
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

kphone 4.2 creates .qt/kphonerc with world-readable permissions, which allows local users to read usernames and SIP passwords.

Vulnerable Product Search on Vulmon Subscribe to Product

kphone kphone 4.2

Vendor Advisories

Sven Dreyer discovered that KPhone, a Voice over IP client for KDE, creates a configuration file world-readable, which could leak sensitive information like SIP passwords The old stable distribution (woody) doesn't contain kphone packages For the stable distribution (sarge) this problem has been fixed in version 410-2sarge1 For the unstable di ...