First published: Thu Nov 12 2015(Updated: )
aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
artsproject aRts | =1.5.10 | |
KDE kdelibs3 | <=3.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7543 is considered a medium severity vulnerability.
To mitigate CVE-2015-7543, users should upgrade to aRts version 1.5.11 or later and ensure they are using KDE kdelibs3 version 3.5.11 or later.
Local users of aRts 1.5.10 and kdelibs3 versions up to 3.5.10 are affected by CVE-2015-7543.
An attacker could potentially hijack IPC communications by pre-creating the temporary directory used by aRts or kdelibs3.
No, CVE-2015-7543 is a local vulnerability that requires access to the affected system.