← Back

CVE-2003-0690

nvd nist
Published: Oct 6, 2003Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.

Affected (27)

Products: Kde: Kde
1 product
Kde
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Kde
Version 1.1.1
Version 1.1.2
Version 1.1
Version 1.2
Version 2.0.1
Version 2.0
Version 2.0_beta
Version 2.1.1
Version 2.1.2
Version 2.1
Version 2.2.1
Version 2.2.2
Version 2.2
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.3a
Version 3.0.4
Version 3.0.5
Version 3.0.5a
Version 3.0.5b
Version 3.0
Version 3.1.1
Version 3.1.1a
Version 3.1.2
Version 3.1.3
Version 3.1

References (26)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.