UBUNTU-CVE-2013-7252

Source
https://ubuntu.com/security/CVE-2013-7252
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-7252.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2013-7252
Upstream
  • CVE-2013-7252
Withdrawn
2025-07-18T16:42:57Z
Published
2015-01-18T18:59:00Z
Modified
2025-07-16T07:31:31.302465Z
Severity
  • Ubuntu - low
Summary
[none]
Details

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.

References

Affected packages

Ubuntu:14.04:LTS / kde-runtime

Package

Name
kde-runtime
Purl
pkg:deb/ubuntu/kde-runtime@4:4.13.3-0ubuntu0.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:4.13.3-0ubuntu0.1

Affected versions

4:4.*
4:4.11.2-0ubuntu1
4:4.11.95-0ubuntu1
4:4.11.97-0ubuntu1
4:4.11.97-0ubuntu2
4:4.12.0-0ubuntu1
4:4.12.1-0ubuntu2
4:4.12.2-0ubuntu1
4:4.12.2-0ubuntu2
4:4.12.3-0ubuntu1
4:4.12.90-0ubuntu1
4:4.12.90-0ubuntu2
4:4.12.95-0ubuntu1
4:4.12.95-0ubuntu2
4:4.12.97-0ubuntu2
4:4.12.97-0ubuntu3
4:4.13.0-0ubuntu1
4:4.13.0-0ubuntu1.1
4:4.13.1-0ubuntu0.1
4:4.13.2-0ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "kde-runtime",
            "binary_version": "4:4.13.3-0ubuntu0.1"
        },
        {
            "binary_name": "kde-runtime-data",
            "binary_version": "4:4.13.3-0ubuntu0.1"
        },
        {
            "binary_name": "kde-runtime-dbg",
            "binary_version": "4:4.13.3-0ubuntu0.1"
        },
        {
            "binary_name": "kdebase-runtime",
            "binary_version": "4:4.13.3-0ubuntu0.1"
        },
        {
            "binary_name": "kdebase-runtime-dbg",
            "binary_version": "4:4.13.3-0ubuntu0.1"
        },
        {
            "binary_name": "khelpcenter4",
            "binary_version": "4:4.13.3-0ubuntu0.1"
        },
        {
            "binary_name": "plasma-scriptengine-javascript",
            "binary_version": "4:4.13.3-0ubuntu0.1"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-7252.json"