CVE-2005-2494: High severity KDE kde vulnerability
Published Sep 6, 2005
·Updated
kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.
Affected Software
10 affected components
KDE kde=3.2.0
KDE kde=3.2.1
KDE kde=3.2.2
KDE kde=3.2.3
KDE kde=3.3.0
KDE kde=3.3.1
KDE kde=3.3.2
KDE kde=3.4.0
KDE kde=3.4.1
KDE kde=3.4.2
Remediation
Patch Available
Event History
Sep 6, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2494?
CVE-2005-2494 has been classified as a high severity vulnerability due to the potential for local users to gain root access.
2
How do I fix CVE-2005-2494?
To mitigate CVE-2005-2494, it is recommended to upgrade to a patched version of KDE that is not affected by this vulnerability.
3
Which versions of KDE are affected by CVE-2005-2494?
KDE versions 3.2.0 up to 3.4.2, including 3.2.1, 3.2.2, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.4.1, and 3.4.2 are affected by CVE-2005-2494.
4
What kind of attack does CVE-2005-2494 involve?
CVE-2005-2494 involves a symlink attack where local users can exploit lock files to gain elevated privileges.
5
Is CVE-2005-2494 a local or remote vulnerability?
CVE-2005-2494 is a local vulnerability that requires access to the affected system to exploit.