PT-2005-5594 · Kde+1 · Kdeedu+5

Ben Burton

+1

·

Published

1970-01-01

·

Updated

2008-09-05

·

CVE-2005-2101

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions kdeedu versions 3.0 through 3.4.2 kdeedu-doc-html (affected versions not specified) kdeedu-data (affected versions not specified) libkdeedu1 (affected versions not specified) libkdeedu-dev (affected versions not specified)
Description The issue involves multiple vulnerabilities in the kdeedu package of the Debian GNU/Linux operating system, which can lead to a breach of protected information integrity. These vulnerabilities can be exploited remotely. Additionally, a specific vulnerability in langen2kvtml, part of KDE 3.0 to 3.4.2, creates insecure temporary files in /tmp with predictable names, allowing local users to overwrite arbitrary files.
Recommendations For kdeedu versions 3.0 through 3.4.2: Update to a version outside of this range to mitigate the risk. For kdeedu-doc-html: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For kdeedu-data: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For libkdeedu1: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For libkdeedu-dev: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03153
BDU:2015-03154
BDU:2015-03155
BDU:2015-03156
BDU:2015-03157
CVE-2005-2101
DSA-818-1

Affected Products

Debian
Kdeedu
Kdeedu-Data
Kdeedu-Doc-Html
Libkdeedu-Dev
Libkdeedu1