← Back

CVE-2001-0178

nvd nist
Published: Mar 26, 2001Modified: Apr 16, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.

Affected (13)

Show all products
1 product
Linux
1 product
Openlinux Edesktop
2 products
Mandrake Linux
Mandrake Linux Corporate Server
1 product
Suse Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Configuration B
12 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.4
Mandrakesoft
Version 6.1
Version 7.0
Version 7.1
Version 7.2
Version 1.0.1
Suse
Version 6.0
Version 6.1
Version 6.2
Version 6.3
Version 6.4
Version 7.0

Timeline

No history available yet.