PT-2017-7222 · Kde+1 · Kdelibs3+2

Yaakov Selkowitz

·

Published

2017-07-25

·

Updated

2018-10-26

·

CVE-2015-7543

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions aRts versions 1.5.10 and earlier kdelibs3 versions 3.5.10 and earlier
Description The issue arises from improper creation of temporary directories, allowing local users to hijack the IPC by pre-creating the temporary directory.
Recommendations For aRts versions 1.5.10 and earlier, consider implementing secure temporary directory creation to prevent IPC hijacking. For kdelibs3 versions 3.5.10 and earlier, ensure proper temporary directory creation to mitigate the risk of IPC hijacking.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7543
DLA-366-1
DLA-367-1
SUSE-SU-2018:3487-1
SUSE-SU-2018_3487-1

Affected Products

Suse
Arts
Kdelibs3