CVE-2018-10380
published 2018-05-08CVE-2018-10380: kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
PriorityP434high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
35.2th percentile
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | kwallet-pam | < kwallet-pam 5.12.1-2 (bookworm) | kwallet-pam 5.12.1-2 (bookworm) |
| kde | plasma | < 5.12.6 | 5.12.6 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hqrj-vwqm-f24h: kwallet-pam in KDE KWallet before 5
ghsa_unreviewed·2022-05-14
CVE-2018-10380 [HIGH] CWE-59 GHSA-hqrj-vwqm-f24h: kwallet-pam in KDE KWallet before 5
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
OSV
CVE-2018-10380: kwallet-pam in KDE KWallet before 5
osv·2018-05-08·CVSS 7.8
CVE-2018-10380 [HIGH] CVE-2018-10380: kwallet-pam in KDE KWallet before 5
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
Debian
CVE-2018-10380: kwallet-pam - kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership ...
vendor_debian·2018·CVSS 7.8
CVE-2018-10380 [HIGH] CVE-2018-10380: kwallet-pam - kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership ...
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
Scope: local
bookworm: resolved (fixed in 5.12.1-2)
bullseye: resolved (fixed in 5.12.1-2)
forky: resolved (fixed in 5.12.1-2)
sid: resolved (fixed in 5.12.1-2)
trixie: resolved (fixed in 5.12.1-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10380 pam-kwallet: Access to privileged files [epel-7]
bugzilla·2018-05-04·CVSS 7.8
CVE-2018-10380 [HIGH] CVE-2018-10380 pam-kwallet: Access to privileged files [epel-7]
CVE-2018-10380 pam-kwallet: Access to privileged files [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update' req
Bugzilla
CVE-2018-10380 pam-kwallet: Access to privileged files
bugzilla·2018-05-04·CVSS 7.8
CVE-2018-10380 [HIGH] CVE-2018-10380 pam-kwallet: Access to privileged files
CVE-2018-10380 pam-kwallet: Access to privileged files
It was found that kwallet-pam was doing file writing and permission changing as root that with correct timing and use of carefully crafted symbolic links could allow a non privileged user to become the owner of any file on the system.
External References:
https://www.kde.org/info/security/advisory-20180503-1.txt
Upstream patches:
https://commits.kde.org/kwallet-pam/2134dec85ce19d6378d03cddfae9e5e464cb24c0
https://commits.kde.org/kwallet-pam/01d4143fda5bddb6dca37b23304dc239a5fb38b5
Discussion:
Created pam-kwallet tracking bugs for this issue:
Affects: epel-7 [bug 1574853]
---
pam-kwallet-5.12.5-3.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.
---
https://bugzilla.suse.com/show_bug.cgi?id=1090863https://commits.kde.org/kwallet-pam/01d4143fda5bddb6dca37b23304dc239a5fb38b5https://commits.kde.org/kwallet-pam/2134dec85ce19d6378d03cddfae9e5e464cb24c0https://commits.kde.org/kwallet-pam/802f305d81f8771c4f4a8bd7fd0e368ffc6f9b3bhttps://commits.kde.org/kwallet-pam/99abc7fde21f40cc6da5feb6ee766cc46fcca1f8https://www.debian.org/security/2018/dsa-4200https://www.kde.org/info/security/advisory-20180503-1.txthttps://bugzilla.suse.com/show_bug.cgi?id=1090863https://commits.kde.org/kwallet-pam/01d4143fda5bddb6dca37b23304dc239a5fb38b5https://commits.kde.org/kwallet-pam/2134dec85ce19d6378d03cddfae9e5e464cb24c0https://commits.kde.org/kwallet-pam/802f305d81f8771c4f4a8bd7fd0e368ffc6f9b3bhttps://commits.kde.org/kwallet-pam/99abc7fde21f40cc6da5feb6ee766cc46fcca1f8https://www.debian.org/security/2018/dsa-4200https://www.kde.org/info/security/advisory-20180503-1.txt
2018-05-08
Published