CVE-2013-7252
Publication date 18 January 2015
Last updated 24 July 2024
Ubuntu priority
kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
kde-runtime | ||
14.04 LTS trusty | Not in release | |
kdebase-runtime | ||
14.04 LTS trusty | Not in release | |
Notes
mdeslaur
fixing this would require migrating existing wallets. 4.12 is switching to a gnupg backend. Marking as ignored, since changes are too intrusive to backport.