kwalletd: Information disclosure Kwalletd password stores are vulnerable to codebook attacks. kwalletd 2016-06-27 2016-06-27 496768 local 4.14.3-r2 4.14.3-r2

Kwalletd is is a credentials management application for KDE.

Kwalletd in KWallet uses Blowfish with ECB mode instead of CBC mode when encrypting the password store.

Local attackers, with access to the password store, could conduct a codebook attack in order to obtain confidential passwords.

There is no known workaround at this time.

All kwalletd users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=kde-apps/kwalletd-4.14.3-r1"
CVE-2013-7252 K_F b-man