CVE-2016-3100
13.07.2016, 15:59
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.Enginsight
Vendor | Product | Version |
---|---|---|
opensuse | leap | 42.1 |
opensuse | opensuse | 13.2 |
kde | kde_frameworks | 𝑥 ≤ 5.22.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References