CVE-2001-0178: Low severity Conectiva Linux vulnerability
Published Mar 26, 2001
·Updated
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
Affected Software
13 affected components
Conectiva Linux=6.0
SUSE SuSE Linux=6.2
Mandrakesoft Mandrake Linux=7.2
Mandrakesoft Mandrake Linux=7.0
Mandrakesoft Mandrake Linux Corporate Server=1.0.1
Mandrakesoft Mandrake Linux=7.1
SUSE SuSE Linux=6.0
SUSE SuSE Linux=6.1
SUSE SuSE Linux=7.0
Caldera Openlinux Edesktop=2.4
SUSE SuSE Linux=6.3
SUSE SuSE Linux=6.4
Mandrakesoft Mandrake Linux=6.1
Remediation
Event History
Mar 26, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0178?
CVE-2001-0178 is considered a security vulnerability that can lead to local privilege escalation.
2
How do I fix CVE-2001-0178?
To fix CVE-2001-0178, update the kdesu program to a version that is 2.2.0-6 or later.
3
Which versions of Linux are affected by CVE-2001-0178?
CVE-2001-0178 affects Conectiva Linux 6.0, SUSE Linux 6.0-7.0, and Mandrake Linux 6.1-7.2.
4
What does CVE-2001-0178 exploit?
CVE-2001-0178 exploits improper verification of the owner of a UNIX socket used in password transmission.
5
Can local users exploit CVE-2001-0178?
Yes, local users can exploit CVE-2001-0178 to steal passwords and potentially gain elevated privileges.