6.9
CVSSv2

CVE-2010-0436

Published: 15/04/2010 Updated: 19/09/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 up to and including 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde sc 4.3.4

kde kde sc 4.3.0

kde kde sc 4.2.2

kde kde sc 4.4.1

kde kde sc 4.3.5

kde kde sc 4.3.1

kde kde sc 4.4.0

kde kde sc 4.4.2

kde kde sc 4.1.2

kde kde sc 3.5.10

kde kde sc 2.2.0

Vendor Advisories

Synopsis Important: kdebase security update Type/Severity Security Advisory: Important Topic Updated kdebase packages that fix one security issue are now available forRed Hat Enterprise Linux 4 and 5The Red Hat Security Response Team has rated this update as havingimportant security impact A Common Vulner ...
Sebastian Krahmer discovered a race condition in the KDE Display Manager (KDM) A local attacker could exploit this to change the permissions on arbitrary files, thus allowing privilege escalation ...
Sebastian Krahmer discovered that a race condition in the KDE Desktop Environment's KDM display manager, allow a local user to elevate privileges to root For the stable distribution (lenny), this problem has been fixed in version 4:359dfsg1-6+lenny1 For the unstable distribution (sid), this problem will be fixed soon We recommend that you up ...