7.2
CVSSv2

CVE-2005-2494

Published: 06/09/2005 Updated: 11/10/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 3.3.1

kde kde 3.3.2

kde kde 3.2.1

kde kde 3.2.2

kde kde 3.4.2

kde kde 3.2.0

kde kde 3.4.0

kde kde 3.4.1

kde kde 3.2.3

kde kde 3.3.0

Vendor Advisories

Ilja van Sprundel discovered a flaw in the lock file handling of kcheckpass A local attacker could exploit this to execute arbitrary code with root privileges ...