First published: Wed Nov 18 1998(Updated: )
KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD FreeBSD | =6.2-stable | |
KDE KDE | =1.0 | |
Linux Kernel | =2.6.20.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0781 is considered a moderate severity vulnerability due to its potential for local users to execute arbitrary commands.
To fix CVE-1999-0781, you should avoid allowing untrusted users to modify the KDEDIR environment variable.
CVE-1999-0781 affects local users on systems running KDE, FreeBSD 6.2-stable, and Linux Kernel 2.6.20.1.
The impact of CVE-1999-0781 includes the ability for local users to execute arbitrary commands, compromising system security.
While CVE-1999-0781 may not be widely exploited in modern systems, it's a reminder of the need for proper environment variable management in software.