CVE-2005-0205
Published May 2, 2005
Last updated 7 years ago
Overview
- Description
- KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.6
- Impact score
- 6.4
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:bernd_wuebben:kppp:2.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DBF32485-71A9-4B7F-BECB-9163E4E66821" }, { "criteria": "cpe:2.3:o:kde:kde:3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F98A556-D640-40F1-92C2-FC262F50F5C8" }, { "criteria": "cpe:2.3:o:kde:kde:3.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7E2C256-8E9F-4D12-ABF4-FECE06B52CAA" }, { "criteria": "cpe:2.3:o:kde:kde:3.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33AF934D-B51B-4A81-BC47-FFEAB9A62C30" }, { "criteria": "cpe:2.3:o:kde:kde:3.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A3096F2-B0F1-45E1-806D-6434DE56619A" }, { "criteria": "cpe:2.3:o:kde:kde:3.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA5560AA-372B-4462-AFF8-8F27A980E507" }, { "criteria": "cpe:2.3:o:kde:kde:3.1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4904CFFD-4CE1-4D65-A7BA-9B06E5B35D07" } ], "operator": "OR" } ] } ]