CVE-2013-2213
Publication date 11 February 2020
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| kdeplasma-addons | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
|
Notes
seth-arnold
This CVE is for an incomplete fix for CVE-2013-2120, which means that it only really applies to packages where the upstream fix for CVE-2013-2120 was used. I believe that is only raring-proposed as of 2013-06-26, but I'm marking this needed for all releases, to ensure the incorrect fix is not used alone.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | Low |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | High |
| Availability impact | None |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |