CVE-2000-0460: Buffer Overflow
Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
KDE kdesudfrom your environment.Uninstall or disable the kdesud component on affected systems (KDE Kde Beta 3) until an official patch or fixed version is released.
- Compensating control
Prevent untrusted local users from executing kdesud and restrict local account access until a fix is available (for example, remove execute permission for non-privileged users, restrict access via filesystem permissions or local access controls, or apply MAC policies to deny execution).
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0460?
CVE-2000-0460 is classified as a high severity vulnerability due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2000-0460?
To fix CVE-2000-0460, you should update KDE to a version that is not vulnerable, such as KDE 1.2 or later.
Who is affected by CVE-2000-0460?
Local users of KDE versions 1.0 to 1.1.2 on Linux systems are affected by CVE-2000-0460.
What type of vulnerability is CVE-2000-0460?
CVE-2000-0460 is a buffer overflow vulnerability related to the manipulation of the DISPLAY environmental variable.
Can CVE-2000-0460 be exploited remotely?
CVE-2000-0460 cannot be exploited remotely, as it requires local access to the system.