CVE-2016-3100
13.07.2016, 15:59
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.Enginsight
| Vendor | Product | Version |
|---|---|---|
| opensuse | leap | 42.1 |
| opensuse | opensuse | 13.2 |
| kde | kde_frameworks | 𝑥 ≤ 5.22.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References