CVE-2001-0178
2.1
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD
Description
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
Affected (13)
Products: Conectiva: Linux · Caldera: Openlinux Edesktop · Mandrakesoft: Mandrake Linux, Mandrake Linux Corporate Server · +1 more
Show all products
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.4 | |
| Version 6.1 | |
| Version 1.0.1 | |
| Version 6.0 |
References (8)
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.