KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.
References
Link | Resource |
---|---|
http://lists.kde.org/?l=kde-devel&m=90221974029738&w=2 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/1639 |
Configurations
History
No history.
Information
Published : 1998-07-11 04:00
Updated : 2017-12-19 02:29
NVD link : CVE-1999-1270
Mitre link : CVE-1999-1270
CVE.ORG link : CVE-1999-1270
JSON object : View
Products Affected
kde
- kde
CWE