CVE-2016-3100

HIGH

Opensuse Leap < 5.22.0 - Information Disclosure

Title source: rule
STIX 2.1

Description

kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/91769
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-07/msg00001.html
Various Sources x_refsource_confirm
https://bugs.kde.org/show_bug.cgi?id=358593
Various Sources x_refsource_confirm
https://www.kde.org/info/security/advisory-20160621-1.txt
Various Sources x_refsource_confirm
https://bugs.kde.org/show_bug.cgi?id=363140

Scores

CVSS v3 8.4
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (3)
kde/kde_frameworks < 5.22.0
opensuse/leap 42.1
opensuse/opensuse 13.2
Published Jul 13, 2016
Tracked Since Feb 18, 2026