KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.
References
Configurations
History
20 Nov 2024, 23:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.kde.org/?l=kde-devel&m=90221974029738&w=2 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/1639 - |
Information
Published : 1998-07-11 04:00
Updated : 2024-11-20 23:30
NVD link : CVE-1999-1270
Mitre link : CVE-1999-1270
CVE.ORG link : CVE-1999-1270
JSON object : View
Products Affected
kde
- kde
CWE