2.1
CVSSv2

CVE-2016-3100

Published: 13/07/2016 Updated: 30/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 8.4 | Impact Score: 5.9 | Exploitability Score: 2.5
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

kinit in KDE Frameworks prior to 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.2

opensuse leap 42.1

kde kde frameworks

Vendor Advisories

Debian Bug report logs - #827476 CVE-2016-3100 Package: kinit; Maintainer for kinit is Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Source for kinit is src:kinit (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 16 Jun 2016 17:54:02 UTC Severity: grave Tags: sec ...