CVE-2005-1920
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.67% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-281
- Affected
- kde/kde · debian/debian linux
- Source
- secalert@redhat.com
References
- http://marc.info/?l=bugtraq&m=112171434023679&w=2Mailing List
- http://secunia.com/advisories/16099Broken Link
- http://secunia.com/advisories/23099Broken Link
- http://security.gentoo.org/glsa/glsa-200611-21.xmlThird Party Advisory
- http://securitytracker.com/id?1014512Broken Link, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2005/dsa-804Third Party Advisory
- http://www.kde.org/info/security/advisory-20050718-1.txtPatch, Vendor Advisory
- http://www.novell.com/linux/security/advisories/2005_18_sr.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-612.htmlBroken Link
- http://www.securityfocus.com/archive/1/427976/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/14297Broken Link, Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9434Broken Link
- http://marc.info/?l=bugtraq&m=112171434023679&w=2Mailing List
- http://secunia.com/advisories/16099Broken Link
- http://secunia.com/advisories/23099Broken Link
- http://security.gentoo.org/glsa/glsa-200611-21.xmlThird Party Advisory
- http://securitytracker.com/id?1014512Broken Link, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2005/dsa-804Third Party Advisory
- http://www.kde.org/info/security/advisory-20050718-1.txtPatch, Vendor Advisory
- http://www.novell.com/linux/security/advisories/2005_18_sr.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-612.htmlBroken Link
- http://www.securityfocus.com/archive/1/427976/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/14297Broken Link, Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9434Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.