Krusader 1.50-beta1 up to 1.70.0 stores passwords for remote connections in cleartext in the bookmark file (krbookmarks.xml), which allows attackers to steal passwords by obtaining the file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Krusader | Krusader | 1.50_beta1 (including) | 1.50_beta1 (including) |
Krusader | Krusader | 1.60.0 (including) | 1.60.0 (including) |
Krusader | Krusader | 1.70.0 (including) | 1.70.0 (including) |
Krusader | Krusader | 1.70.0_beta1 (including) | 1.70.0_beta1 (including) |
Krusader | Ubuntu | dapper | * |
Krusader | Ubuntu | devel | * |
Krusader | Ubuntu | edgy | * |
Krusader | Ubuntu | feisty | * |
Krusader | Ubuntu | gutsy | * |
Krusader | Ubuntu | hardy | * |
Krusader | Ubuntu | intrepid | * |
Krusader | Ubuntu | jaunty | * |
Krusader | Ubuntu | karmic | * |