First published: Wed Oct 05 2005(Updated: )
Uim 0.4.x before 0.4.9.1 and 0.5.0 and earlier does not properly handle the LIBUIM_VANILLA environment variable when a suid or sgid application is linked to libuim, such as immodule for Qt, which allows local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
UIM | <=0.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3149 has a high severity as it allows local users to gain elevated privileges through improper handling of environment variables.
To fix CVE-2005-3149, upgrade to Uim version 0.4.9.1 or later for the vulnerable 0.4.x series, or use version 0.5.1 or later.
CVE-2005-3149 affects Uim versions prior to 0.4.9.1 and 0.5.0 or earlier.
Local users of systems running affected Uim versions are vulnerable to CVE-2005-3149.
Suid or sgid applications linked to libuim, such as immodule for Qt, are impacted by CVE-2005-3149.