Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Davide Madrisan

#53342of 53,633
2.1Total CVSS
Vulnerabilities · 1
PT-2005-1440
2.1
2005-02-11
Kde · Kde · CVE-2005-0365
**Name of the Vulnerable Software and Affected Versions** KDE versions 3.2.x through 3.3.x **Description** The issue concerns the dcopidlng script, which creates temporary files with predictable filenames. This predictability allows local users to perform a symlink attack, enabling them to overwrite arbitrary files. **Recommendations** For KDE versions 3.2.x through 3.3.x, consider restricting access to the dcopidlng script until a patch is available to prevent local users from exploiting this issue. As a temporary workaround, avoid using the dcopidlng script for tasks that involve creating temporary files.