Vulnerabilities > CVE-2005-2101 - Unspecified vulnerability in KDE

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
kde
nessus

Summary

langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-818.NASL
    descriptionJavier Fernandez-Sanguino Pena discovered that langen2kvhtml from the kvoctrain package from the kdeedu suite creates temporary files in an insecure fashion. This leaves them open for symlink attacks.
    last seen2020-06-01
    modified2020-06-02
    plugin id19787
    published2005-10-05
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19787
    titleDebian DSA-818-1 : kdeedu - insecure temporary files
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2005-159.NASL
    descriptionBen Burton notified the KDE security team about several tempfile handling related vulnerabilities in langen2kvtml, a conversion script for kvoctrain. This vulnerability was initially discovered by Javier Fernández-Sanguino Peña. The script uses known filenames in /tmp which allow an local attacker to overwrite files writeable by the user (manually) invoking the conversion script. The updated packages have been patched to correct this problem.
    last seen2020-06-01
    modified2020-06-02
    plugin id19914
    published2005-10-05
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19914
    titleMandrake Linux Security Advisory : kdeedu (MDKSA-2005:159)