KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9334 | signature vdb entry broken link |
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000864 | vendor advisory broken link |
http://secunia.com/advisories/12276/ | patch vendor advisory broken link third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16963 | third party advisory vdb entry |
http://www.debian.org/security/2004/dsa-539 | third party advisory vendor advisory |
http://security.gentoo.org/glsa/glsa-200408-13.xml | third party advisory vendor advisory |
http://marc.info/?l=bugtraq&m=109225538901170&w=2 | mailing list |
http://www.kde.org/info/security/advisory-20040811-1.txt | patch vendor advisory |