FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

kdelibs insecure temporary file handling

Affected packages
kdelibs <= 3.2.3_3

Details

VuXML ID 603fe36d-ec9d-11d8-b913-000c41e2cdad
Discovery 2004-08-11
Entry 2004-08-12

According to a KDE Security Advisory, KDE may sometimes create temporary files without properly checking the ownership and type of the target path. This could allow a local attacker to cause KDE applications to overwrite arbitrary files.

References

CVE Name CVE-2004-0689
CVE Name CVE-2004-0690
URL ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-dcopserver.patch
URL ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-kstandarddirs.patch
URL http://www.kde.org/info/security/advisory-20040811-1.txt
URL http://www.kde.org/info/security/advisory-20040811-2.txt