Lucene search

K
cveMitreCVE-2005-0365
HistoryMay 02, 2005 - 4:00 a.m.

CVE-2005-0365

2005-05-0204:00:00
mitre
web.nvd.nist.gov
37
cve
2005
0365
dcopidlng
kde
security vulnerability
symlink attack
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

5.1%

The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.

Affected configurations

Nvd
Node
kdekdeMatch3.2.x
OR
kdekdeMatch3.3.x
VendorProductVersionCPE
kdekde3.2.xcpe:2.3:o:kde:kde:3.2.x:*:*:*:*:*:*:*
kdekde3.3.xcpe:2.3:o:kde:kde:3.3.x:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

5.1%