Vulnerability Name: | CVE-1999-1270 (CCN-1639) | ||||||||
Assigned: | 1998-07-11 | ||||||||
Published: | 1998-07-11 | ||||||||
Updated: | 2017-12-19 | ||||||||
Summary: | KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-1999-1270 Source: CCN Type: KDE-DEVEL Mailing List KMail/PGP security bug (?) Source: MISC Type: Vendor Advisory http://lists.kde.org/?l=kde-devel&m=90221974029738&w=2 Source: CCN Type: K Desktop Environment (KDE) Web site K Desktop Environment Home Source: CCN Type: OSVDB ID: 11965 KDE KMail Command Line PGP Passphrase Disclosure Source: XF Type: UNKNOWN kde-kmail-passphrase-leak(1639) Source: XF Type: UNKNOWN kde-kmail-passphrase-leak(1639) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |