4
CVSSv2

CVE-2006-2449

Published: 15/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 4 | Impact Score: 6.9 | Exploitability Score: 1.9
VMScore: 356
Vector: AV:L/AC:H/Au:N/C:C/I:N/A:N

Vulnerability Summary

KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 3.2.2

kde kde 3.2.3

kde kde 3.4.3

kde kde 3.5

kde kde 3.2

kde kde 3.2.1

kde kde 3.4.1

kde kde 3.4.2

kde kde 3.3

kde kde 3.3.1

kde kde 3.5.2

kde kde 3.5.3

kde kde 3.3.2

kde kde 3.4

Vendor Advisories

Ludwig Nussel discovered that kdm managed the ~/dmrc file in an insecure way By performing a symlink attack, a local user could exploit this to read arbitrary files on the system, like private files of other users, /etc/shadow, and similarly sensitive data ...