PT-2005-1075 · Kde+1 · Kppp+4

Published

2005-02-28

·

Updated

2017-10-11

·

CVE-2005-0205

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kdenetwork versions 2.2.2 through 3.1.3 kdenetwork-devel version 3.1.3 kdenetwork-ppp version 2.2.2 KPPP version 2.1.2 and earlier in KDE 3.1.5 and earlier
Description The issue may lead to a breach of confidentiality, integrity, and availability of protected information. It can be exploited locally, potentially allowing attackers to gain control over DNS name resolution by manipulating file descriptors for domain sockets. This could enable local users to read and write to sensitive files such as /etc/hosts and /etc/resolv.conf.
Recommendations For kdenetwork versions 2.2.2 through 3.1.3, consider restricting access to sensitive files until a patch is available. For kdenetwork-devel version 3.1.3, restrict the use of the kdenetwork-devel package to minimize the risk of exploitation. For kdenetwork-ppp version 2.2.2, avoid using the kdenetwork-ppp package until the issue is resolved. For KPPP version 2.1.2 and earlier in KDE 3.1.5 and earlier, consider disabling the setuid root functionality for KPPP until a fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06787
BDU:2015-06788
BDU:2015-06789
BDU:2015-06790
CVE-2005-0205
DSA-692-1
RHSA-2005:175
RHSA-2005_175

Affected Products

Kppp
Red Hat
Kdenetwork
Kdenetwork-Devel
Kdenetwork-Ppp