KDE kdesu Insecure Temporary File Creation Vulnerability
BID:2669
Info
KDE kdesu Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 2669 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 25 2001 12:00AM |
| Updated: | Apr 25 2001 12:00AM |
| Credit: | Reported to Bugtraq in a Red Hat Security Advisory published on April 25, 2001 and posted to Bugtraq on April 30, 2001. |
| Vulnerable: |
Redhat kdelibs-sound-devel-2.1.1-5.i386.rpm Redhat kdelibs-sound-2.1.1-5.i386.rpm Redhat kdelibs-devel-2.1.1-5.i386.rpm Redhat kdelibs-2.1.1-5.i386.rpm Redhat arts-2.1.1-5.i386.rpm KDE kdelibs 2.1.1 KDE kdelibs 2.1 KDE kdelibs 2.0.1 KDE kdelibs 2.0 |
| Not Vulnerable: |
KDE kdelibs 2.1.2 |
Discussion
KDE kdesu Insecure Temporary File Creation Vulnerability
KDESu is a frontend for su(1) used by many KDE programs for the execution of commands with elevated privileges.
The kdesu program creates a world-readable temporary file when exchanging authentication information. As a result, it may be possible for a local attacker to use this information to gain access to the X server and compromise the account accessed by kdesu.
KDESu is a frontend for su(1) used by many KDE programs for the execution of commands with elevated privileges.
The kdesu program creates a world-readable temporary file when exchanging authentication information. As a result, it may be possible for a local attacker to use this information to gain access to the X server and compromise the account accessed by kdesu.