XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747428
http://www.openwall.com/lists/oss-security/2014/05/20/5