PT-2017-7222 · Kde+1 · Kdelibs3+2
Yaakov Selkowitz
·
Published
2017-07-25
·
Updated
2018-10-26
·
CVE-2015-7543
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
aRts versions 1.5.10 and earlier
kdelibs3 versions 3.5.10 and earlier
Description
The issue arises from improper creation of temporary directories, allowing local users to hijack the IPC by pre-creating the temporary directory.
Recommendations
For aRts versions 1.5.10 and earlier, consider implementing secure temporary directory creation to prevent IPC hijacking.
For kdelibs3 versions 3.5.10 and earlier, ensure proper temporary directory creation to mitigate the risk of IPC hijacking.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Arts
Kdelibs3