CVE-2005-0011
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.92% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- kde/kde
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/14306Patch
- http://www.gentoo.org/security/en/glsa/glsa-200502-23.xmlVendor Advisory
- http://www.kde.org/info/security/advisory-20050215-1.txtPatch, Vendor Advisory
- http://www.redhat.com/archives/fedora-announce-list/2005-February/msg00044.htmlVendor Advisory
- http://secunia.com/advisories/14306Patch
- http://www.gentoo.org/security/en/glsa/glsa-200502-23.xmlVendor Advisory
- http://www.kde.org/info/security/advisory-20050215-1.txtPatch, Vendor Advisory
- http://www.redhat.com/archives/fedora-announce-list/2005-February/msg00044.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.