KDE K-Mail File Creation Vulnerability

BID:300

Info

KDE K-Mail File Creation Vulnerability

Bugtraq ID: 300
Class: Origin Validation Error
CVE:
Remote: No
Local: Yes
Published: Jun 09 1999 12:00AM
Updated: Jun 09 1999 12:00AM
Credit: This vulnerability was discovered by Brian Mitchell <[email protected]>.
Vulnerable: Redhat Linux 6.0
KDE KDE 1.1.1
KDE KDE 1.1
Caldera OpenLinux 2.2
Caldera OpenLinux 1.3
Caldera kdenetwork 1.1.1 -1
+ Caldera OpenLinux 2.2
Not Vulnerable: Caldera kdenetwork 1.1.1 -2

Discussion

KDE K-Mail File Creation Vulnerability

KMail is a mail user agent that comes with the kdenetwork package, part of the K Desktop Environment. A vulnerability in the way KMail creates temporary files to save attachments may allow malicious users to overwrite any file that user running KMail has permissions to.

When viewing messages with attachments KMail creates a directory under /tmp in which to store the attachments with a predictable name of the form "kmail<pid of kmail>". KMail fails to verify whether the directory exists and follows symbolic links. This allows local attackers to create or overwrite files with contents they can select in any directory and/or file writable by the user running KMail.

References

KDE K-Mail File Creation Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report