CVE-2013-7252
 
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.
kwalletd en KWallet anterior a las aplicaciones KDE 14.12.0 utiliza Blowfish con el modo ECB en lugar del modo CBC cuando codifica el almacén de contraseñas, lo que facilita a atacantes adivinar las contraseñas a través de un ataque de libro de códigos (codebook).
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-01-02 CVE Reserved
- 2015-01-18 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2024-08-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2014/01/02/3 | Mailing List | |
http://www.openwall.com/lists/oss-security/2015/01/09/7 | Mailing List | |
http://www.securityfocus.com/bid/67716 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=1048168 | Issue Tracking |
URL | Date | SRC |
---|---|---|
http://gaganpreet.in/blog/2013/07/24/kwallet-security-analysis | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://www.kde.org/info/security/advisory-20150109-1.txt | 2016-08-02 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201606-19 | 2016-08-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kde Search vendor "Kde" | Kde Applications Search vendor "Kde" for product "Kde Applications" | <= 14.11.3 Search vendor "Kde" for product "Kde Applications" and version " <= 14.11.3" | - |
Affected
|