First published: Wed Sep 06 2006(Updated: )
The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password by attempting to log in multiple times.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat KDE Base | =3.5.4_0.4.fc5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3742 is considered a high severity vulnerability due to its ability to allow unauthorized access to user accounts.
To fix CVE-2006-3742, update the KDE PAM configuration to prevent password caching on KDM logins.
CVE-2006-3742 specifically affects KDE version 3.5.4_0.4.fc5.
Yes, attackers can exploit CVE-2006-3742 remotely by repeatedly attempting to log in without needing the correct password.
Yes, patches are available that can be applied to mitigate the vulnerability associated with CVE-2006-3742.