CVE-2000-0530: High severity Caldera OpenLinux vulnerability
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
KDE Kde Beta 3from your environment.Uninstall KDE Kde Beta 3 from affected systems or cease use of this KDE build until a vendor-supplied fix is available.
- Remove
Remove
SCO OpenLinux Serverfrom your environment.Uninstall or disable the affected SCO OpenLinux Server components if they are not required, or avoid providing local access to untrusted users until a vendor remedy is available.
- Compensating control
Restrict and harden local user access and file permissions: disable or remove untrusted local accounts, restrict shell/login access to trusted administrators, and ensure configuration files and directories are not writable by unprivileged local users to prevent arbitrary file overwrite.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0530?
CVE-2000-0530 is classified as a medium to high severity vulnerability due to its potential to allow local users to overwrite arbitrary files.
How does CVE-2000-0530 affect the KApplication class?
CVE-2000-0530 affects the KApplication class by allowing local users to exploit its file management capabilities to overwrite files.
Who is affected by CVE-2000-0530?
Users of KDE version 1.1.2 and SCO OpenLinux Server version 2.4 are particularly affected by CVE-2000-0530.
How can I fix CVE-2000-0530?
To fix CVE-2000-0530, ensure that you upgrade to a later version of KDE that addresses this vulnerability.
What types of systems are vulnerable to CVE-2000-0530?
CVE-2000-0530 primarily affects systems running the KDE 1.1.2 desktop environment and SCO OpenLinux Server 2.4.