CVE-2005-0365: Low severity KDE kde vulnerability
Published Feb 11, 2005
·Updated
The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
Affected Software
2 affected components
KDE kde=3.3.x
KDE kde=3.2.x
Remediation
Patch Available
Patch Available
Patch Available
Event History
Feb 11, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0365?
CVE-2005-0365 is categorized as a moderate severity vulnerability.
2
How do I fix CVE-2005-0365?
To mitigate CVE-2005-0365, upgrade KDE to version 3.4 or later.
3
What systems are affected by CVE-2005-0365?
The vulnerability affects KDE versions 3.2.x and 3.3.x.
4
What type of attack does CVE-2005-0365 allow?
CVE-2005-0365 allows local users to perform symlink attacks to overwrite arbitrary files.
5
Who is at risk from CVE-2005-0365?
Local users on systems running affected versions of KDE are at risk from CVE-2005-0365.