PT-2022-17033 · Kde+2 · Kde Kcron+2

Carlos López

·

Published

2022-02-26

·

Updated

2023-10-12

·

CVE-2022-24986

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KDE KCron versions prior to 21.12.3
Description The issue allows an attacker to potentially intercept a temporary file and run unauthorized commands. This is due to the reuse of a filename in the /tmp directory during an editing session.
Recommendations For versions prior to 21.12.3, update to version 21.12.3 or later to resolve the issue.

Fix

Race Condition

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1439
ALT-PU-2022-1586
CVE-2022-24986
OPENSUSE-SU-2024:11881-1

Affected Products

Alt Linux
Debian
Kde Kcron