CVE-1999-1270

KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.
Configurations

Configuration 1 (hide)

cpe:2.3:o:kde:kde:1.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:30

Type Values Removed Values Added
References () http://lists.kde.org/?l=kde-devel&m=90221974029738&w=2 - Vendor Advisory () http://lists.kde.org/?l=kde-devel&m=90221974029738&w=2 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/1639 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/1639 -

Information

Published : 1998-07-11 04:00

Updated : 2024-11-20 23:30


NVD link : CVE-1999-1270

Mitre link : CVE-1999-1270

CVE.ORG link : CVE-1999-1270


JSON object : View

Products Affected

kde

  • kde