KDE 3.1 Global Configuration Files Insecure Default Permissions Vulnerability
BID:9047
Info
KDE 3.1 Global Configuration Files Insecure Default Permissions Vulnerability
| Bugtraq ID: | 9047 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 14 2003 12:00AM |
| Updated: | Nov 14 2003 12:00AM |
| Credit: | This vulnerability was discovered by Martin Fallon <[email protected]>. |
| Vulnerable: |
KDE KDE 3.1 |
| Not Vulnerable: | |
Discussion
KDE 3.1 Global Configuration Files Insecure Default Permissions Vulnerability
It has been reported that the KDE 3.1 kdeglobals, as well as other configuration files may be stored with insecure permissions on some distributions. Specifically, it has been reported that SuSE 8.2 stores the kdeglobals configuration file, and other files, world-writeable. This may make it possible for a malicious local user to carry out a number of attacks on any other user of the KDE graphical user interface.
It has been reported that the KDE 3.1 kdeglobals, as well as other configuration files may be stored with insecure permissions on some distributions. Specifically, it has been reported that SuSE 8.2 stores the kdeglobals configuration file, and other files, world-writeable. This may make it possible for a malicious local user to carry out a number of attacks on any other user of the KDE graphical user interface.
Exploit / POC
KDE 3.1 Global Configuration Files Insecure Default Permissions Vulnerability
An example of a modified kdeglobals file has been provided and can be seen by viewing the appropriate message reference.
An example of a modified kdeglobals file has been provided and can be seen by viewing the appropriate message reference.
Solution / Fix
KDE 3.1 Global Configuration Files Insecure Default Permissions Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
KDE 3.1 Global Configuration Files Insecure Default Permissions Vulnerability
References:
References:
- KDE 3.1 - Suse 8.2 - kdeglobals world writable (Martin Fallon
)