The Popular URL capability (popularurls.cpp) in Krusader 1.60.0 and 1.70.0-beta1 saves passwords in cleartext in the krusaderrc file when the user enters URLs containing passwords in the panel URL field, which might allow attackers to access other sites.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Krusader | Krusader | 1.60.0 (including) | 1.60.0 (including) |
Krusader | Krusader | 1.70.0_beta1 (including) | 1.70.0_beta1 (including) |
Krusader | Ubuntu | dapper | * |
Krusader | Ubuntu | devel | * |
Krusader | Ubuntu | edgy | * |
Krusader | Ubuntu | feisty | * |
Krusader | Ubuntu | gutsy | * |