The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kde | Kde | 3.2.x (including) | 3.2.x (including) |
Kde | Kde | 3.3.x (including) | 3.3.x (including) |
Red Hat Enterprise Linux 4 | RedHat | kdelibs-6:3.3.1-3.6 | * |
Kdelibs | Ubuntu | dapper | * |
Kdelibs | Ubuntu | devel | * |
Kdelibs | Ubuntu | edgy | * |
Kdelibs | Ubuntu | feisty | * |