PT-2006-7555 · Kde+1 · Xfonts-Konsole+4

Ludwig Nussel

·

Published

1970-01-01

·

Updated

2018-10-18

·

CVE-2006-2449

CVSS v2.0

4.0

Medium

VectorAV:L/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions KDE Display Manager (KDM) versions 3.2.0 through 3.5.3 kdebase versions prior to 3.5.2-r2 kdebase3-kdm (affected versions not specified) xfonts-konsole (affected versions not specified)
Description The issue allows local users to read arbitrary files via a symlink attack related to the session type for login, potentially leading to a breach of protected information. The exploitation of this issue can be carried out locally.
Recommendations For KDE Display Manager (KDM) versions 3.2.0 through 3.5.3, update to a version later than 3.5.3 to resolve the issue. For kdebase versions prior to 3.5.2-r2, update to version 3.5.2-r2 or later. For kdebase3-kdm, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For xfonts-konsole, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02787
BDU:2015-04881
BDU:2015-09508
CVE-2006-2449
DSA-1156
RHSA-2006:0548
RHSA-2006_0548

Affected Products

Kde Display Manager
Red Hat
Kdebase
Kdebase3-Kdm
Xfonts-Konsole