{"api_version":"1","generated_at":"2026-07-23T05:35:55+00:00","cve":"CVE-2005-1920","urls":{"html":"https://cve.report/CVE-2005-1920","api":"https://cve.report/api/cve/CVE-2005-1920.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1920","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1920"},"summary":{"title":"CVE-2005-1920","description":"The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.","state":"PUBLISHED","assigner":"redhat","published_at":"2005-07-26 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-281","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/14297","name":"http://www.securityfocus.com/bid/14297","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"KDE Kate, KWrite Local Backup File Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.debian.org/security/2005/dsa-804","name":"http://www.debian.org/security/2005/dsa-804","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-804-1 kdelibs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/16099","name":"http://secunia.com/advisories/16099","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Secunia - Advisories - KDE Kate / KWrite Backup File Insecure File Permissions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=112171434023679&w=2","name":"http://marc.info/?l=bugtraq&m=112171434023679&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"'[KDE Security Advisory]: Kate backup file permission leak' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kde.org/info/security/advisory-20050718-1.txt","name":"http://www.kde.org/info/security/advisory-20050718-1.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9434","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9434","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1014512","name":"http://securitytracker.com/id?1014512","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - KDE Kate/Kwrite May Disclose Backup Files to Local Users or Remote Authenticated Users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200611-21.xml","name":"http://security.gentoo.org/glsa/glsa-200611-21.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Linux Documentation\n--\n  Kile: Incorrect backup file permission","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2005_18_sr.html","name":"http://www.novell.com/linux/security/advisories/2005_18_sr.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/427976/100/0/threaded","name":"http://www.securityfocus.com/archive/1/427976/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23099","name":"http://secunia.com/advisories/23099","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Gentoo update for kile - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-612.html","name":"http://www.redhat.com/support/errata/RHSA-2005-612.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1920","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1920","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1920","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1920","vulnerable":"1","versionEndIncluding":"3.4.0","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"kde","cpe5":"kde","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:06:57.747Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"SUSE-SR:2005:018","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2005_18_sr.html"},{"name":"14297","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14297"},{"name":"oval:org.mitre.oval:def:9434","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9434"},{"name":"DSA-804","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2005/dsa-804"},{"name":"1014512","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014512"},{"name":"FLSA:178606","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://www.securityfocus.com/archive/1/427976/100/0/threaded"},{"name":"20050718 [KDE Security Advisory]: Kate backup file permission leak","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112171434023679&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kde.org/info/security/advisory-20050718-1.txt"},{"name":"GLSA-200611-21","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200611-21.xml"},{"name":"16099","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16099"},{"name":"23099","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23099"},{"name":"RHSA-2005:612","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2005-612.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-07-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"SUSE-SR:2005:018","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2005_18_sr.html"},{"name":"14297","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14297"},{"name":"oval:org.mitre.oval:def:9434","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9434"},{"name":"DSA-804","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2005/dsa-804"},{"name":"1014512","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014512"},{"name":"FLSA:178606","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://www.securityfocus.com/archive/1/427976/100/0/threaded"},{"name":"20050718 [KDE Security Advisory]: Kate backup file permission leak","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112171434023679&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kde.org/info/security/advisory-20050718-1.txt"},{"name":"GLSA-200611-21","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200611-21.xml"},{"name":"16099","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16099"},{"name":"23099","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23099"},{"name":"RHSA-2005:612","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2005-612.html"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2005-1920","datePublished":"2005-07-26T04:00:00.000Z","dateReserved":"2005-06-08T00:00:00.000Z","dateUpdated":"2024-08-07T22:06:57.747Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-07-26 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-281","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:kde:kde:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndIncluding":"3.4.0","matchCriteriaId":"A8FBCB14-BB97-4340-B5A5-5759A7D417DC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*","matchCriteriaId":"A2E0C1F8-31F5-4F61-9DF7-E49B43D3C873"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1920","Ordinal":"1","Title":"CVE-2005-1920","CVE":"CVE-2005-1920","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1920","Ordinal":"1","NoteData":"The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.","Type":"Description","Title":"CVE-2005-1920"},{"CveYear":"2005","CveId":"1920","Ordinal":"2","NoteData":"2005-07-26","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1920","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}