CVE-2006-2449KDE vulnerability

8 documents6 sources
Severity
4.0MEDIUMNVD
EPSS
0.1%
top 78.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 15
Latest updateMay 1

Description

KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.

CVSS vector

AV:L/AC:H/C:C/I:N/A:NExploitability: 1.9 | Impact: 6.9

Affected Packages1 packages

NVDkde/kde14 versions+13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rf2c-jr84-7pmj: KDE Display Manager (KDM) in KDE 32022-05-01
CVEList
CVE-2006-2449: KDE Display Manager (KDM) in KDE 32006-06-15

📋Vendor Advisories

2
Ubuntu
kdm vulnerability2006-06-15
Red Hat
security flaw2006-06-14

💬Community

3
Bugzilla
CVE-2006-2449 security flaw2018-08-16
Bugzilla
CVE-2006-2449 kdm file disclosure2006-06-14
Bugzilla
CVE-2005-2494 kdebase- kcheckpass privilege escalation, CVE-2006-2449 kdebase- KDM symlink attack vulnerability2006-02-05
CVE-2006-2449 — KDE vulnerability | cvebase