Vulnerability Name: | CVE-2013-2074 (CCN-84171) | ||||||||||||||||||||
Assigned: | 2013-05-13 | ||||||||||||||||||||
Published: | 2013-05-13 | ||||||||||||||||||||
Updated: | 2014-02-25 | ||||||||||||||||||||
Summary: | kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message. | ||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: MISC Type: UNKNOWN http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=707776 Source: MITRE Type: CNA CVE-2013-2074 Source: CCN Type: KDE Web site K Desktop Environment -Conquer your Desktop! Source: UBUNTU Type: UNKNOWN USN-1842-1 Source: MLIST Type: UNKNOWN [oss-security] 20130510 CVE request: password exposure in kdelibs when showing "internal server error" messages Source: MLIST Type: UNKNOWN [oss-security] 20130510 Re: CVE request: password exposure in kdelibs when showing "internal server error" messages Source: OSVDB Type: UNKNOWN 93244 Source: CCN Type: BID-59808 kdelibs CVE-2013-2074 Local Password Disclosure Vulnerability Source: MISC Type: UNKNOWN http://xorl.wordpress.com/2013/05/22/cve-2013-2074-kde-kdelibs-password-exposure/ Source: CONFIRM Type: Vendor Advisory https://bugs.kde.org/show_bug.cgi?id=319428 Source: CCN Type: Red Hat Bugzilla Bug 961981 CVE-2013-2074 kdelibs: prints passwords contained in HTTP URLs in error messages Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=961981 Source: XF Type: UNKNOWN kdelibs-cve20132074-info-disc(84171) Source: CCN Type: KDELibs GIT Repository Revision 65d736da Source: MISC Type: UNKNOWN https://projects.kde.org/projects/kde/kdelibs/repository/revisions/65d736dab592bced4410ccfa4699de89f78c96ca/diff/kioslave/http/http.cpp Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-2074 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |