PT-2017-7222 · Kde+1 · Kdelibs3+2

Yaakov Selkowitz

·

Publicado

2017-07-25

·

Atualizado

2018-10-26

·

CVE-2015-7543

CVSS v2.0

4.4

Média

VetorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions aRts versions 1.5.10 and earlier kdelibs3 versions 3.5.10 and earlier
Description The issue arises from improper creation of temporary directories, allowing local users to hijack the IPC by pre-creating the temporary directory.
Recommendations For aRts versions 1.5.10 and earlier, consider implementing secure temporary directory creation to prevent IPC hijacking. For kdelibs3 versions 3.5.10 and earlier, ensure proper temporary directory creation to mitigate the risk of IPC hijacking.

Exploit

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7543
DLA-366-1
DLA-367-1
SUSE-SU-2018:3487-1
SUSE-SU-2018_3487-1

Produtos afetados

Suse
Arts
Kdelibs3