CVE-2000-0371: Low severity KDE kde vulnerability
The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
libmediatool (KDE mediatool)from your environment.Uninstall or remove the libmediatool library / KDE mediatool from affected systems until a vendor-supplied patch or fixed package is available to eliminate the symlink attack vector.
- Compensating control
Restrict local access and execution of the KDE mediatool to trusted accounts only (apply host-level ACLs or remove execute permission for untrusted users). Prevent untrusted local users from running the vulnerable component or from writing to directories where the tool may create files.
- Operational
Audit the filesystem and system logs for unexpected or recently created files in sensitive locations and remediate any files created by local users that may indicate exploitation; monitor for suspicious activity by local accounts until a vendor fix is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0371?
CVE-2000-0371 has been classified as a moderate severity vulnerability.
How do I fix CVE-2000-0371?
To mitigate CVE-2000-0371, users should upgrade to the latest version of the KDE software that addresses this vulnerability.
What does CVE-2000-0371 exploit?
CVE-2000-0371 exploits a symlink vulnerability in the libmediatool library used by KDE, allowing local users to create arbitrary files.
Who is affected by CVE-2000-0371?
CVE-2000-0371 affects local users on systems running specific versions of the KDE software, particularly versions 1.1 and 1.1.1.
When was CVE-2000-0371 disclosed?
CVE-2000-0371 was disclosed in the year 2000.