CVE-1999-0735: Medium severity KDE K-Mail vulnerability
KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
KMailfrom your environment.Uninstall KMail (or otherwise remove it from affected hosts) until an official vendor patch/fixed version is available.
- Compensating control
Prevent local users from exploiting symlink attacks in temporary user directories used by KMail — for example, restrict write/create permissions on those temporary directories, isolate KMail runtime files to directories not writable by untrusted local users, or use filesystem/isolation controls to block following attacker-controlled symlinks.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0735?
CVE-1999-0735 is considered a medium severity vulnerability that allows local users to exploit privilege escalation.
How do I fix CVE-1999-0735?
To fix CVE-1999-0735, upgrade to KDE K-Mail version 1.1 or later, ensuring temporary user directories are secured against symlink attacks.
Who is affected by CVE-1999-0735?
Users of KDE K-Mail versions up to and including 1.1 on local machines are affected by CVE-1999-0735.
What type of attack does CVE-1999-0735 involve?
CVE-1999-0735 involves a symlink attack that can be exploited to gain elevated privileges on a local system.
Is CVE-1999-0735 specific to KDE K-Mail?
Yes, CVE-1999-0735 specifically affects KDE K-Mail and its handling of temporary user directories.