CVE-2018-10380: High severity kde plasma workspace vulnerability
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-10380?
CVE-2018-10380 is a vulnerability in kwallet-pam in KDE KWallet before version 5.12.6 that allows local users to obtain ownership of arbitrary files via a symlink attack.
How does CVE-2018-10380 affect KDE KWallet?
CVE-2018-10380 affects KDE KWallet before version 5.12.6.
What is the severity of CVE-2018-10380?
CVE-2018-10380 has a severity rating of 7.8 (high).
How can I fix CVE-2018-10380?
You can fix CVE-2018-10380 by updating to KDE KWallet version 5.12.6 or higher.
Where can I find more information about CVE-2018-10380?
You can find more information about CVE-2018-10380 at the following references: [Bugzilla](https://bugzilla.suse.com/show_bug.cgi?id=1090863), [KDE Commits](https://commits.kde.org/kwallet-pam/01d4143fda5bddb6dca37b23304dc239a5fb38b5), [KDE Commits](https://commits.kde.org/kwallet-pam/2134dec85ce19d6378d03cddfae9e5e464cb24c0).