CVE-2005-1920

CWE-2818 documents7 sources
Severity
7.5HIGH
EPSS
2.8%
top 13.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 26
Latest updateMay 1

Description

The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDkde/kde3.23.4.0

Also affects: Debian Linux 3.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2p38-wq56-wg8h: The (1) Kate and (2) Kwrite applications in KDE KDE 32022-05-01
CVEList
CVE-2005-1920: The (1) Kate and (2) Kwrite applications in KDE KDE 32005-07-26

📋Vendor Advisories

2
Ubuntu
KDE library vulnerability2005-07-21
Red Hat
security flaw2005-07-18

📐Framework References

1
CWE
Improper Preservation of Permissions

💬Community

1
Bugzilla
CVE-2005-1920 security flaw2018-08-16