LWN.net Logo

Pardus alert 2010-50 (kdm kdebase-workspace)

From:  Eren Turkay <eren@pardus.org.tr>
To:  pardus-security@pardus.org.tr
Subject:  [Pardus-security] [PLSA 2010-50] KDM: Privilege Escalation
Date:  Tue, 20 Apr 2010 09:42:44 +0300 (EEST)
Message-ID:  <20100420064244.CE678A7AB17@lider.pardus.org.tr>
Archive-link:  Article, Thread

------------------------------------------------------------------------ Pardus Linux Security Advisory 2010-50 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2010-04-20 Severity: 3 Type: Local ------------------------------------------------------------------------ Summary ======= A security issue has been fixed in KDE, which can be exploited by malicious, local users to gain escalated privileges. Description =========== CVE-2010-0436: Race condition in backend/ctrl.c in KDM in KDE allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm. Affected packages: Pardus 2009: kdm, all before 4.3.5-104-65 kdebase-workspace, all before 4.3.5-104-65 Resolution ========== There are update(s) for kdm, kdebase-workspace. You can update them via Package Manager or with a single command from console: pisi up kdm kdebase-workspace References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=12677 * http://www.kde.org/info/security/advisory-20100413-1.txt * http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0436 ------------------------------------------------------------------------ _______________________________________________ Pardus-security mailing list Pardus-security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds