VulnerabilityModified
CVE-2022-24986
Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.
HIGH 7.8EPSS 0.25%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362, CWE-668
- Affected
- kde/kcron
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2022/02/25/3Mailing List, Third Party Advisory
- https://apps.kde.org/kcron/Product
- http://www.openwall.com/lists/oss-security/2022/02/25/3Mailing List, Third Party Advisory
- https://apps.kde.org/kcron/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.