The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "4:4.13.3-0ubuntu0.1", "binary_name": "kdeplasma-addons" }, { "binary_version": "4:4.13.3-0ubuntu0.1", "binary_name": "kdeplasma-addons-dbg" }, { "binary_version": "4:4.13.3-0ubuntu0.1", "binary_name": "plasma-containments-addons" }, { "binary_version": "4:4.13.3-0ubuntu0.1", "binary_name": "plasma-dataengines-addons" }, { "binary_version": "4:4.13.3-0ubuntu0.1", "binary_name": "plasma-runners-addons" }, { "binary_version": "4:4.13.3-0ubuntu0.1", "binary_name": "plasma-wallpapers-addons" }, { "binary_version": "4:4.13.3-0ubuntu0.1", "binary_name": "plasma-widget-kdeobservatory" }, { "binary_version": "4:4.13.3-0ubuntu0.1", "binary_name": "plasma-widget-kimpanel" }, { "binary_version": "4:4.13.3-0ubuntu0.1", "binary_name": "plasma-widget-lancelot" }, { "binary_version": "4:4.13.3-0ubuntu0.1", "binary_name": "plasma-widgets-addons" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "kdeplasma-addons-data" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "kdeplasma-addons-dbg" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "kwin-addons" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "kwin-addons-dbgsym" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "plasma-dataengines-addons" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "plasma-dataengines-addons-dbgsym" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "plasma-runners-addons" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "plasma-runners-addons-dbgsym" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "plasma-wallpapers-addons" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "plasma-wallpapers-addons-dbgsym" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "plasma-widgets-addons" }, { "binary_version": "4:5.5.5-0ubuntu1", "binary_name": "plasma-widgets-addons-dbgsym" } ] }