CVE-2010-0436

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.

References

ftp://ftp.kde.org/pub/kde/security_patches/kdebase-workspace-4.3.5-CVE-2010-0436.diff

http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039533.html

http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.html

http://rhn.redhat.com/errata/RHSA-2010-0348.html

http://secunia.com/advisories/39419

http://secunia.com/advisories/39481

http://secunia.com/advisories/39506

http://www.debian.org/security/2010/dsa-2037

http://www.kde.org/info/security/advisory-20100413-1.txt

http://www.securityfocus.com/bid/39467

http://www.vupen.com/english/advisories/2010/0879

https://bugzilla.redhat.com/show_bug.cgi?id=570613

https://exchange.xforce.ibmcloud.com/vulnerabilities/57823

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9999

Details

Source: MITRE

Published: 2010-04-15

Updated: 2017-09-19

Type: CWE-362

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

Tenable Plugins

View all (23 total)

IDNameProductFamilySeverity
79961GLSA-201412-08 : Multiple packages, Multiple vulnerabilities fixed in 2010NessusGentoo Local Security Checks
critical
68031Oracle Linux 4 / 5 : kdebase (ELSA-2010-0348)NessusOracle Linux Local Security Checks
medium
60781Scientific Linux Security Update : kdebase on SL4.x, SL5.x i386/x86_64NessusScientific Linux Local Security Checks
medium
54878Slackware 13.0 / current : kdebase-workspace (SSA:2010-110-02)NessusSlackware Local Security Checks
medium
50921SuSE 11 Security Update : kdm (SAT Patch Number 2136)NessusSuSE Local Security Checks
medium
49851SuSE 10 Security Update : kdm (ZYPP Patch Number 6941)NessusSuSE Local Security Checks
medium
47499Fedora 11 : kde-l10n-4.4.3-1.fc11 / kdeaccessibility-4.4.3-1.fc11.1 / kdeadmin-4.4.3-1.fc11.1 / etc (2010-8547)NessusFedora Local Security Checks
medium
47498Fedora 12 : kde-l10n-4.4.3-1.fc12 / kdeaccessibility-4.4.3-1.fc12.1 / kdeadmin-4.4.3-1.fc12.1 / etc (2010-8544)NessusFedora Local Security Checks
medium
47440Fedora 13 : kdebase-workspace-4.4.2-5.fc13 (2010-6605)NessusFedora Local Security Checks
medium
47415Fedora 12 : PyQt4-4.7.2-2.fc12 / kdeaccessibility-4.4.2-1.fc12 / kdeadmin-4.4.2-1.fc12 / etc (2010-6096)NessusFedora Local Security Checks
medium
47414Fedora 11 : PyQt4-4.7.2-2.fc11 / kdeaccessibility-4.4.2-1.fc11 / kdeadmin-4.4.2-1.fc11 / etc (2010-6077)NessusFedora Local Security Checks
medium
46298RHEL 4 / 5 : kdebase (RHSA-2010:0348)NessusRed Hat Local Security Checks
medium
45582CentOS 4 / 5 : kdebase (CESA-2010:0348)NessusCentOS Local Security Checks
medium
45576Ubuntu 8.10 / 9.04 / 9.10 : kdebase-workspace vulnerability (USN-932-1)NessusUbuntu Local Security Checks
medium
45559Debian DSA-2037-1 : kdm (kdebase) - race conditionNessusDebian Local Security Checks
medium
45548Mandriva Linux Security Advisory : kdebase (MDVSA-2010:074)NessusMandriva Local Security Checks
medium
45539SuSE 10 Security Update : kdm (ZYPP Patch Number 6942)NessusSuSE Local Security Checks
medium
45538openSUSE Security Update : kde4-kdm (openSUSE-SU-2010:0112-1)NessusSuSE Local Security Checks
medium
45536openSUSE Security Update : kde4-kdm (kde4-kdm-2134)NessusSuSE Local Security Checks
medium
45534openSUSE Security Update : fileshareset (fileshareset-2204)NessusSuSE Local Security Checks
medium
45533openSUSE Security Update : kde4-kdm (kde4-kdm-2134)NessusSuSE Local Security Checks
medium
45531openSUSE Security Update : fileshareset (fileshareset-2204)NessusSuSE Local Security Checks
medium
45529FreeBSD : KDM -- local privilege escalation vulnerability (3987c5d1-47a9-11df-a0d5-0016d32f24fb)NessusFreeBSD Local Security Checks
medium