KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kde | Kde | 1.1 (including) | 1.1 (including) |
Kde | Kde | 1.1.1 (including) | 1.1.1 (including) |
Kde | Kde | 1.1.2 (including) | 1.1.2 (including) |
Kde | Kde | 1.2 (including) | 1.2 (including) |
Kde | Kde | 2.0 (including) | 2.0 (including) |
Kde | Kde | 2.0.1 (including) | 2.0.1 (including) |
Kde | Kde | 2.0_beta (including) | 2.0_beta (including) |
Kde | Kde | 2.1 (including) | 2.1 (including) |
Kde | Kde | 2.1.1 (including) | 2.1.1 (including) |
Kde | Kde | 2.1.2 (including) | 2.1.2 (including) |
Kde | Kde | 2.2 (including) | 2.2 (including) |
Kde | Kde | 2.2.1 (including) | 2.2.1 (including) |
Kde | Kde | 2.2.2 (including) | 2.2.2 (including) |
Kde | Kde | 3.0 (including) | 3.0 (including) |
Kde | Kde | 3.0.1 (including) | 3.0.1 (including) |
Kde | Kde | 3.0.2 (including) | 3.0.2 (including) |
Kde | Kde | 3.0.3 (including) | 3.0.3 (including) |
Kde | Kde | 3.0.3a (including) | 3.0.3a (including) |
Kde | Kde | 3.0.4 (including) | 3.0.4 (including) |
Kde | Kde | 3.0.5 (including) | 3.0.5 (including) |
Kde | Kde | 3.0.5a (including) | 3.0.5a (including) |
Kde | Kde | 3.0.5b (including) | 3.0.5b (including) |
Kde | Kde | 3.1 (including) | 3.1 (including) |
Kde | Kde | 3.1.1 (including) | 3.1.1 (including) |
Kde | Kde | 3.1.1a (including) | 3.1.1a (including) |
Kde | Kde | 3.1.2 (including) | 3.1.2 (including) |
Kde | Kde | 3.1.3 (including) | 3.1.3 (including) |
Kdebase | Ubuntu | dapper | * |
Kdebase | Ubuntu | devel | * |
Kdebase | Ubuntu | edgy | * |
Kdebase | Ubuntu | feisty | * |
Xorg | Ubuntu | dapper | * |
Xorg | Ubuntu | devel | * |
Xorg | Ubuntu | edgy | * |
Xorg | Ubuntu | feisty | * |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
Red Hat Enterprise Linux WS version 2.1 | RedHat | * | |
Red Hat Enterprise Linux WS version 2.1 | RedHat | * | |
Red Hat Linux 7.1 | RedHat | * | |
Red Hat Linux 7.1 | RedHat | * | |
Red Hat Linux 7.2 | RedHat | * | |
Red Hat Linux 7.2 | RedHat | * | |
Red Hat Linux 7.3 | RedHat | * | |
Red Hat Linux 7.3 | RedHat | * | |
Red Hat Linux 8.0 | RedHat | * | |
Red Hat Linux 8.0 | RedHat | * | |
Red Hat Linux 9 | RedHat | * | |
Red Hat Linux 9 | RedHat | * | |
Red Hat Linux Advanced Workstation 2.1 | RedHat | * | |
Red Hat Linux Advanced Workstation 2.1 | RedHat | * |