CVE-2005-3149: Medium severity uim Uim vulnerability
Uim 0.4.x before 0.4.9.1 and 0.5.0 and earlier does not properly handle the LIBUIMVANILLA environment variable when a suid or sgid application is linked to libuim, such as immodule for Qt, which allows local users to gain privileges.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3149?
CVE-2005-3149 has a high severity as it allows local users to gain elevated privileges through improper handling of environment variables.
How do I fix CVE-2005-3149?
To fix CVE-2005-3149, upgrade to Uim version 0.4.9.1 or later for the vulnerable 0.4.x series, or use version 0.5.1 or later.
Which Uim versions are affected by CVE-2005-3149?
CVE-2005-3149 affects Uim versions prior to 0.4.9.1 and 0.5.0 or earlier.
Who is vulnerable to CVE-2005-3149?
Local users of systems running affected Uim versions are vulnerable to CVE-2005-3149.
What applications are impacted by CVE-2005-3149?
Suid or sgid applications linked to libuim, such as immodule for Qt, are impacted by CVE-2005-3149.