CVE-2013-2120

NameCVE-2013-2120
DescriptionThe %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs710497

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kdeplasma-addons (PTS)buster4:5.14.5.1-1fixed
bullseye4:5.20.5-1fixed
bookworm4:5.27.5-2fixed
sid, trixie4:5.27.10-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kdeplasma-addonssource(unstable)4:5.3.2-2low710497

Notes

[jessie] - kdeplasma-addons <no-dsa> (Minor issue)
[wheezy] - kdeplasma-addons <no-dsa> (Minor issue)
[squeeze] - kdeplasma-addons <no-dsa> (Minor issue)
Original fix https://projects.kde.org/projects/kde/kdeplasma-addons/repository/revisions/36a1fe49cb70f717c4a6e9eeee2c9186503a8dce not sufficient

Search for package or bug name: Reporting problems