J-Security Center

Title: KDE kdesu Insecure Temporary File Creation Vulnerability

Severity: MODERATE

Description:

KDESu is a frontend for su(1) used by many KDE programs for the execution of commands with elevated privileges. It is included by default with KDE's libraries.

The kdesu program creates a world-readable temporary file when exchanging authentication information. This file contains sensitive authorization information used by xauth(1) to add an authorization entry for process owner's display.

By predicting when such a temporary file will be created and the name of a file, a local attacker could use the authorization information to gain access to the X server and compromise the account accessed by kdesu.

With access to the X server, an attacker may be able to monitor keystrokes or watch X applications.

Affected Products:

  • KDE KDE 2.0.0
  • KDE KDE 2.0.1
  • KDE KDE 2.1.0
  • KDE KDE 2.1.1
  • KDE kdelibs 2.0.0
  • KDE kdelibs 2.0.1
  • KDE kdelibs 2.1.0
  • KDE kdelibs 2.1.1
  • RedHat Linux 7.1.0
  • RedHat arts-2.1.1-5.i386.rpm 0.0.0
  • RedHat kdelibs-2.1.1-5.i386.rpm 0.0.0
  • RedHat kdelibs-devel-2.1.1-5.i386.rpm 0.0.0
  • RedHat kdelibs-sound-2.1.1-5.i386.rpm 0.0.0
  • RedHat kdelibs-sound-devel-2.1.1-5.i386.rpm 0.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.