The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "kdeplasma-addons", "binary_version": "4:4.13.3-0ubuntu0.1" }, { "binary_name": "kdeplasma-addons-dbg", "binary_version": "4:4.13.3-0ubuntu0.1" }, { "binary_name": "plasma-containments-addons", "binary_version": "4:4.13.3-0ubuntu0.1" }, { "binary_name": "plasma-dataengines-addons", "binary_version": "4:4.13.3-0ubuntu0.1" }, { "binary_name": "plasma-runners-addons", "binary_version": "4:4.13.3-0ubuntu0.1" }, { "binary_name": "plasma-wallpapers-addons", "binary_version": "4:4.13.3-0ubuntu0.1" }, { "binary_name": "plasma-widget-kdeobservatory", "binary_version": "4:4.13.3-0ubuntu0.1" }, { "binary_name": "plasma-widget-kimpanel", "binary_version": "4:4.13.3-0ubuntu0.1" }, { "binary_name": "plasma-widget-lancelot", "binary_version": "4:4.13.3-0ubuntu0.1" }, { "binary_name": "plasma-widgets-addons", "binary_version": "4:4.13.3-0ubuntu0.1" } ], "ubuntu_priority": "low" }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "kdeplasma-addons-data", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "kdeplasma-addons-dbg", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "kwin-addons", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "kwin-addons-dbgsym", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "plasma-dataengines-addons", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "plasma-dataengines-addons-dbgsym", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "plasma-runners-addons", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "plasma-runners-addons-dbgsym", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "plasma-wallpapers-addons", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "plasma-wallpapers-addons-dbgsym", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "plasma-widgets-addons", "binary_version": "4:5.5.5-0ubuntu1" }, { "binary_name": "plasma-widgets-addons-dbgsym", "binary_version": "4:5.5.5-0ubuntu1" } ], "ubuntu_priority": "low" }