CVE-2005-0078: Medium severity KDE kde vulnerability
Published Jan 29, 2005
·Updated
The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.
Affected Software
28 affected components
KDE kde=2.2.1
KDE kde=3.0_beta_1
KDE kde=2.0
KDE kde=3.0.2
redhat Enterprise Linux Desktop=3.0
KDE kde=2.2
redhat Enterprise Linux=3.0
redhat Enterprise Linux=2.1
KDE kde=2.0.1
KDE kde=2.2_beta1
Debian Debian Linux=3.0
redhat Enterprise Linux=2.1
KDE kde=2.1
KDE kde=3.0.1
redhat Linux Advanced Workstation=2.1
KDE kde=2.1_beta2
KDE kde=3.0_beta_2
KDE kde=3.0.4
KDE kde=3.0
KDE kde=1.1.2
KDE kde=1.1.1
redhat Enterprise Linux=3.0
redhat Enterprise Linux=2.1
KDE kde=1.1
KDE kde=1.0
redhat Enterprise Linux=3.0
KDE kde=3.0.3
KDE kde=2.1_beta1
Remediation
Patch Available
Patch Available
Event History
Jan 29, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0078?
CVE-2005-0078 is considered medium severity due to the potential for attackers with physical access to exploit it.
2
How do I fix CVE-2005-0078?
To fix CVE-2005-0078, upgrade to KDE version 3.0.5 or later which addresses this vulnerability.
3
What versions of KDE are affected by CVE-2005-0078?
KDE versions prior to 3.0.5, including versions 2.0 to 3.0.4, are affected by CVE-2005-0078.
4
What type of attack does CVE-2005-0078 allow?
CVE-2005-0078 allows attackers with physical access to crash the screen saver and gain access to the desktop session.
5
Is physical access required to exploit CVE-2005-0078?
Yes, physical access is required to exploit CVE-2005-0078 as it involves interacting directly with the system.