Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > June 2006 > KDE Security Advisory: KDM symlink attack vulnerability

June 2006

KDE Security Advisory: KDM symlink attack vulnerability

ID: 00418
Ref: 407/2006
Date: 15 June 2006:14:20:09
Version: 1

Title: KDE Security Advisory: KDM symlink attack vulnerability
Abstract:
Vendors affected: KDE
Operating systems affected: KDE
Applications affected: KDE

Title
=====

KDE Security Advisory: KDM symlink attack vulnerability

Detail
======

KDM allows the user to select the session type for login. This setting is
permanently stored in the user home directory. By using a symlink attack,
KDM can be tricked into allowing the user to read file content that would
otherwise be unreadable to this particular user. This vulnerability was
discovered and reported by Ludwig Nussel.



KDE Security Advisory: KDM symlink attack vulnerability
Original Release Date: 2006-06-14
URL: http://www.kde.org/info/security/advisory-20060614-1.txt

0. References

CVE-2006-2449


1. Systems affected:

KDM as shipped with KDE 3.2.0 up to including 3.5.3. KDE 3.1.x and
older and newer versions than KDE 3.5.3 are not affected.


2. Overview:

KDM allows the user to select the session type for login. This
setting is permanently stored in the user home directory. By
using a symlink attack, KDM can be tricked into allowing the
user to read file content that would otherwise be unreadable
to this particular user. This vulnerability was discovered
and reported by Ludwig Nussel.


3. Impact:

KDM might allow a normal user to read the content of /etc/shadow
or other files, which allows compromising the privacy of another
user or even the security of the whole system.

4. Solution:

Source code patches have been made available which fix these
vulnerabilities. Contact your OS vendor / binary package provider
for information about how to obtain updated binary packages.


5. Patch:

A patch for KDE 3.4.0 - KDE 3.5.3 is available from
ftp://ftp.kde.org/pub/kde/security_patches :

9daecff07d57dabba35da247e752916a post-3.5.0-kdebase-kdm.diff

A patch for KDE 3.3.x is available from
ftp://ftp.kde.org/pub/kde/security_patches :

f2e1424d97f2cd18674bef833274c5e3 post-3.3.0-kdebase-kdm.diff

A patch for KDE 3.2.x is available from
ftp://ftp.kde.org/pub/kde/security_patches :

8aa6b41cccca4216c6eb1cf705c2370a post-3.2.0-kdebase-kdm.diff

  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |