First published: Tue May 16 2000(Updated: )
The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE KDE | =2.0_beta | |
KDE KDE | =1.1.1 | |
KDE KDE | =1.1 | |
KDE KDE | =1.2 | |
=1.1 | ||
=1.1.1 | ||
=1.2 | ||
=2.0_beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0393 has been assessed as a high severity vulnerability due to the potential privilege escalation it allows.
To fix CVE-2000-0393, it is recommended to upgrade to a version of KDE that implements proper privilege management.
CVE-2000-0393 affects KDE versions 1.1, 1.1.1, 1.2, and 2.0_beta.
CVE-2000-0393 is classified as a privilege escalation vulnerability.
Users running the affected versions of KDE are at risk of privilege escalation attacks through the kscd program.