CVE-2004-0690: Medium severity kde kde vulnerability
Published Sep 14, 2004
·Updated
The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.
Affected Software
1 affected component
KDE kde=3.2.1
Remediation
Patch Available
Patch Available
Event History
Sep 14, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0690?
CVE-2004-0690 is considered a local privilege escalation vulnerability.
2
What causes CVE-2004-0690?
CVE-2004-0690 is caused by a symlink attack on DCOP files located in the /tmp directory.
3
How do I fix CVE-2004-0690?
To fix CVE-2004-0690, upgrade KDE to version 3.2.4 or later.
4
Who is affected by CVE-2004-0690?
Local users on systems running KDE versions 3.2.3 and earlier are affected by CVE-2004-0690.
5
Is CVE-2004-0690 easily exploitable?
Yes, CVE-2004-0690 can be easily exploited by local users with access to the /tmp directory.