CVE-2005-1920
published 2005-07-26CVE-2005-1920: The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original…
PriorityP427high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.67%
88.5th percentile
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| kde | kde | 3.2 – 3.4.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
KDE library vulnerability
vendor_ubuntu·2005-07-21
CVE-2005-1920 KDE library vulnerability
Title: KDE library vulnerability
Summary: KDE library vulnerability
Kate and Kwrite create a backup file before saving a modified file.
These backup files were created with default permissions, even if the
original file had more strict permissions set, so that other local
users could possibly read the backup file even if they are not
permitted to read the original file.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-07-18·CVSS 7.5
CVE-2005-1920 [HIGH] security flaw
security flaw
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.
GHSA
GHSA-2p38-wq56-wg8h: The (1) Kate and (2) Kwrite applications in KDE KDE 3
ghsa_unreviewed·2022-05-01
CVE-2005-1920 [MEDIUM] CWE-281 GHSA-2p38-wq56-wg8h: The (1) Kate and (2) Kwrite applications in KDE KDE 3
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=112171434023679&w=2http://secunia.com/advisories/16099http://secunia.com/advisories/23099http://security.gentoo.org/glsa/glsa-200611-21.xmlhttp://securitytracker.com/id?1014512http://www.debian.org/security/2005/dsa-804http://www.kde.org/info/security/advisory-20050718-1.txthttp://www.novell.com/linux/security/advisories/2005_18_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2005-612.htmlhttp://www.securityfocus.com/archive/1/427976/100/0/threadedhttp://www.securityfocus.com/bid/14297https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9434http://marc.info/?l=bugtraq&m=112171434023679&w=2http://secunia.com/advisories/16099http://secunia.com/advisories/23099http://security.gentoo.org/glsa/glsa-200611-21.xmlhttp://securitytracker.com/id?1014512http://www.debian.org/security/2005/dsa-804http://www.kde.org/info/security/advisory-20050718-1.txthttp://www.novell.com/linux/security/advisories/2005_18_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2005-612.htmlhttp://www.securityfocus.com/archive/1/427976/100/0/threadedhttp://www.securityfocus.com/bid/14297https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9434
2005-07-26
Published