PT-2010-5638 · Kde+1 · Kdebase-Bin+19

Sebastian Krahmer

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2010-0436

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions KDE Software Compilation (SC) versions 2.2.0 through 4.4.2 kdebase-devel versions 3.3.1 through 3.5.4 kdebase versions 3.3.1 through 3.5.4 kdebase-data (affected versions not specified) kdebase-doc (affected versions not specified) kdebase-doc-html (affected versions not specified) kdebase-dbg (affected versions not specified) kdebase-dev (affected versions not specified) kdebase-bin (affected versions not specified) kdebase-bin-kde3 (affected versions not specified) kdebase-kio-plugins (affected versions not specified) kdm (affected versions not specified) khelpcenter (affected versions not specified) konsole (affected versions not specified) kdeeject (affected versions not specified) kdesktop (affected versions not specified) libkonq4 (affected versions not specified) libkonq4-dev (affected versions not specified) kdepasswd (affected versions not specified) kdeprint (affected versions not specified)
Description The issue is related to multiple vulnerabilities in various KDE packages, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally. A race condition in the backend/ctrl.c file of KDM in KDE Software Compilation (SC) allows local users to change the permissions of arbitrary files and gain privileges by blocking the removal of a certain directory that contains a control socket. This is due to improper interaction with ksm.
Recommendations For KDE Software Compilation (SC) versions 2.2.0 through 4.4.2, consider updating to a version outside of this range to mitigate the risk. For kdebase-devel versions 3.3.1 through 3.5.4, consider updating to a version outside of this range to mitigate the risk. For kdebase versions 3.3.1 through 3.5.4, consider updating to a version outside of this range to mitigate the risk. For kdebase-data, kdebase-doc, kdebase-doc-html, kdebase-dbg, kdebase-dev, kdebase-bin, kdebase-bin-kde3, kdebase-kio-plugins, kdm, khelpcenter, konsole, kdeeject, kdesktop, libkonq4, libkonq4-dev, kdepasswd, and kdeprint, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01782
BDU:2015-01784
BDU:2015-01785
BDU:2015-01788
BDU:2015-01789
BDU:2015-02127
BDU:2015-02128
BDU:2015-02129
BDU:2015-02130
BDU:2015-02131
BDU:2015-02132
BDU:2015-02133
BDU:2015-02134
BDU:2015-02135
BDU:2015-02136
BDU:2015-02137
BDU:2015-03506
BDU:2015-03507
BDU:2015-06783
BDU:2015-06784
BDU:2015-06785
BDU:2015-06786
BDU:2015-08595
BDU:2015-08596
BDU:2015-08597
BDU:2015-08598
CVE-2010-0436
DSA-2037-1
OPENSUSE-SU-2024:10023-1
RHSA-2010:0348
RHSA-2010_0348

Affected Products

Kde Software Compilation
Red Hat
Kdebase
Kdebase-Bin
Kdebase-Bin-Kde3
Kdebase-Data
Kdebase-Dbg
Kdebase-Devel
Kdebase-Doc
Kdebase-Doc-Html
Kdebase-Kio-Plugins
Kdeeject
Kdepasswd
Kdeprint
Kdesktop
Kdm
Help Center
Konsole
Libkonq4
Libkonq4-Dev