CVE-2014-3800 Information

Description

XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml which allows local users to obtain user names and passwords by reading this file.

Reference

http://trac.xbmc.org/ticket/15198 http://www.openwall.com/lists/oss-security/2014/05/20/4 http://www.openwall.com/lists/oss-security/2014/05/20/5 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747428

Share on: