CVE-1999-1269: Low severity kde kde beta 3 vulnerability
Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
KDE Kde Beta 3from your environment.Uninstall or remove the KDE Beta 3 screensaver component (or KDE Beta 3 entirely) from affected systems until an official fix is available.
- Configuration
Disable the KDE screensaver to prevent exploitation of the .kss.pid symlink vulnerability in KDE Beta 3.
KDE screensaver enabled = false - Compensating control
Restrict or remove untrusted local user accounts and enforce least-privilege on systems running KDE Beta 3 to reduce the risk of local symlink attacks against the .kss.pid file.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1269?
CVE-1999-1269 is considered a local vulnerability due to its exploitation requiring local user access.
How do I fix CVE-1999-1269?
To fix CVE-1999-1269, ensure that the KDE beta 3 installation is updated to a version that addresses this vulnerability.
Who is affected by CVE-1999-1269?
Local users of KDE beta 3 are affected by CVE-1999-1269 due to the symlink attack vulnerability.
What type of attack does CVE-1999-1269 describe?
CVE-1999-1269 describes a symlink attack that allows local users to overwrite arbitrary files.
What software versions are impacted by CVE-1999-1269?
CVE-1999-1269 specifically affects KDE beta 3, particularly its initial version.