2.1
CVSSv2

CVE-2013-2120

Published: 11/02/2020 Updated: 21/02/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 8.4 | Impact Score: 5.9 | Exploitability Score: 2.5
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet prior to 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent malicious users to bypass authentication via a brute-force attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde paste applet

Vendor Advisories

Debian Bug report logs - #710497 kdeplasma-addons: CVE-2013-2120 Package: kdeplasma-addons; Maintainer for kdeplasma-addons is Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Source for kdeplasma-addons is src:kdeplasma-addons (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> ...