First published: Thu Aug 19 2004(Updated: )
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE KDE | <=3.3.0 | |
KDE KDE | <3.3 | |
Debian GNU/Linux | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0689 is classified as a moderate severity vulnerability.
To fix CVE-2004-0689, upgrade KDE to version 3.3.0 or later.
The vulnerability may allow local users to create or truncate arbitrary files, potentially leading to data loss or corruption.
CVE-2004-0689 affects KDE versions prior to 3.3.0.
CVE-2004-0689 is not a remote vulnerability and requires local access for exploitation.