PT-2017-7222 · Kde+1 · Kdelibs3+2
Yaakov Selkowitz
·
Publicado
2017-07-25
·
Atualizado
2018-10-26
·
CVE-2015-7543
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
aRts versions 1.5.10 and earlier
kdelibs3 versions 3.5.10 and earlier
Description
The issue arises from improper creation of temporary directories, allowing local users to hijack the IPC by pre-creating the temporary directory.
Recommendations
For aRts versions 1.5.10 and earlier, consider implementing secure temporary directory creation to prevent IPC hijacking.
For kdelibs3 versions 3.5.10 and earlier, ensure proper temporary directory creation to mitigate the risk of IPC hijacking.
Exploit
Correção
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suse
Arts
Kdelibs3