Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-0205
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-0205

Description:
KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.

CVE Status:
Candidate

References:

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-175.html

IDEFENSE
  http://www.idefense.com/application/poi/display?id=208&type=vulnerabilities

DEBIAN
  http://www.debian.org/security/2005/dsa-692

CONFIRM
  http://www.kde.org/info/security/advisory-20050228-1.txt

CONECTIVA
  http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000934


Return to the previous page.