[kde 3.5.6] kdesu prints password characters typed with dead keys to console
Bug #82271 reported by
jcfp
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
kdebase (Ubuntu) |
New
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: kdebase-bin
When running kdesu from konsole, it prints characters in clear text if they are entered with help of dead keys (like " + a = ä, or " + SPACEBAR = "):
$ kdesu kate
sending IMStart with 0 chars to 0x8178010
sending IMEnd with 1 chars to 0x8178010, text=ä
sending IMStart with 0 chars to 0x8178010
sending IMEnd with 1 chars to 0x8178010, text="
Thus revealing (parts of) the password. Nothing is printed with 'normal' characters.
edgy with kde 3.5.6 from kubuntu.org
To post a comment you must log in.
This bug and bug 82275 are probably related.