MGASA-2015-0044

Source
https://advisories.mageia.org/MGASA-2015-0044.html
Import Source
https://advisories.mageia.org/MGASA-2015-0044.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0044
Upstream
  • CVE-2013-7252
Published
2015-01-31T13:23:52Z
Modified
2026-04-16T06:24:48.038787632Z
Summary
Updated kdebase4-runtime packages fix CVE-2013-7252 and several bugs
Details

Updated kdebase4-runtime packages fix security vulnerability:

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack (CVE-2013-7252).

This update also fixes some additional issues: - encoding in KDEsuDialog (mga#14851) - kio_sftp can corrupts files when reading (bko#342391) - use euro currency for Lithuania - save the default file manager, email client and browser in mimeapps.list [Default Applications] for a better interoperability with most of GTK applications (mga#4461)

References
Credits

Affected packages

Mageia:4 / kdebase4-runtime

Package

Name
kdebase4-runtime
Purl
pkg:rpm/mageia/kdebase4-runtime?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.5-1.3.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0044.json"