Description: A vulnerability has been reported in KDE, which can be exploited by malicious, local users to gain knowledge of sensitive information.
KDM allows users to specify the session type for login, which is stored permanently in the user's home directory. This information is read insecurely by the "ReadDmrc()" function and can be exploited via symlink attacks to read the contents of any file on the system.
The vulnerability affects KDE 3.2.0 through 3.5.3.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.