Jump to content

Advisories MDVSA-2010:074: kdebase


paul
 Share

Recommended Posts

A vulnerability has been found and corrected in kdm

(kdebase/kdebase4-workspace):

 

KDM contains a race condition that allows local attackers to make

arbitrary files on the system world-writeable. This can happen

while KDM tries to create its control socket during user login. This

vulnerability has been discovered by Sebastian Krahmer from the SUSE

Security Team (CVE-2010-0436).

 

It is adviced to reboot the computer after applying the updated

packages in order to the security fix to take full effect.

 

Packages for 2008.0 are provided for Corporate Desktop 2008.0

customers.

 

The updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...