MGASA-2015-0044

    Dashboard / Vulnerabilities / MGASA-2015-0044

    MGASA-2015-0044

    Published: 31 Jan 2015Last Modified: 16 Apr 2026
    Upstream:

    Summary: Updated kdebase4-runtime packages fix CVE-2013-7252 and several bugs

    Details: Updated kdebase4-runtime packages fix security vulnerability: kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack (CVE-2013-7252). This update also fixes some additional issues: - encoding in KDEsuDialog (mga#14851) - kio_sftp can corrupts files when reading (bko#342391) - use euro currency for Lithuania - save the default file manager, email client and browser in mimeapps.list [Default Applications] for a better interoperability with most of GTK applications (mga#4461)

    Affected packages

    Package

    Name: kdebase4-runtime

    Purl: pkg:rpm/mageia/kdebase4-runtime?arch=source&distro=mageia-4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.12.5-1.3.mga4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High