CVE-2023-52723

NameCVE-2023-52723
DescriptionIn KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3809-1
Debian Bugs1069163

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libkf5ksieve (PTS)buster4:18.08.3-2vulnerable
buster (security)4:18.08.3-2+deb10u1fixed
bullseye4:20.08.3-1vulnerable
bookworm4:22.12.3-1vulnerable
sid, trixie4:22.12.3-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libkf5ksievesourcebuster4:18.08.3-2+deb10u1DLA-3809-1
libkf5ksievesource(unstable)4:22.12.3-21069163

Notes

[bookworm] - libkf5ksieve <no-dsa> (Minor issue, will be fixed via spu)
[bullseye] - libkf5ksieve <no-dsa> (Minor issue, will be fixed via ospu)
https://www.openwall.com/lists/oss-security/2024/04/25/1
Fixed by: https://invent.kde.org/pim/libksieve/-/commit/6b460ba93ac4ac503ba039d0b788ac7595120db1 (v23.03.80)

Search for package or bug name: Reporting problems