Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

KDE Plaintext Password Disclosure Vulnerability

KDE is reported prone to a plaintext password disclosure vulnerability. This issue presents itself when a link to a remote file is created by various KDE applications including Konqueror Web browser. The URI may contain authentication credentials to access the remote resource such as a Samba share.

An attacker can disclose these credentials by accessing the potentially world readable link reference file created by KDE.







 

Privacy Statement
Copyright 2008, SecurityFocus