CVE-2014-3800

XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xbmc:xbmc:13.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:08

Type Values Removed Values Added
References () http://trac.xbmc.org/ticket/15198 - () http://trac.xbmc.org/ticket/15198 -
References () http://www.openwall.com/lists/oss-security/2014/05/20/4 - () http://www.openwall.com/lists/oss-security/2014/05/20/4 -
References () http://www.openwall.com/lists/oss-security/2014/05/20/5 - () http://www.openwall.com/lists/oss-security/2014/05/20/5 -
References () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747428 - () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747428 -

Information

Published : 2014-08-07 11:13

Updated : 2024-11-21 02:08


NVD link : CVE-2014-3800

Mitre link : CVE-2014-3800

CVE.ORG link : CVE-2014-3800


JSON object : View

Products Affected

xbmc

  • xbmc
CWE
CWE-264

Permissions, Privileges, and Access Controls