LWN.net Logo

kdeedu: tempfile handling vulnerabilities

Package(s):kdeedu CVE #(s):CAN-2005-2101
Created:August 15, 2005 Updated:September 22, 2005
Description: Ben Burton notified the KDE security team about several tempfile handling related vulnerabilities in langen2kvtml, a conversion script for kvoctrain. The script must be manually invoked. The script uses known filenames in /tmp which allow an local attacker to overwrite files writeable by the user invoking the conversion script.
Alerts:
Debian DSA-818-1 2005-09-22
Mandriva MDKSA-2005:159 2005-09-06
Fedora FEDORA-2005-744 2005-08-16
Fedora FEDORA-2005-745 2005-08-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds