Vulnerability Description
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kde | Kde | < 3.3 |
| Debian | Debian Linux | 3.0 |
Related Weaknesses (CWE)
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000864Broken Link
- http://marc.info/?l=bugtraq&m=109225538901170&w=2Mailing List
- http://secunia.com/advisories/12276/Broken LinkPatchVendor Advisory
- http://security.gentoo.org/glsa/glsa-200408-13.xmlThird Party Advisory
- http://www.debian.org/security/2004/dsa-539Third Party Advisory
- http://www.kde.org/info/security/advisory-20040811-1.txtPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16963Third Party AdvisoryVDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Broken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000864Broken Link
- http://marc.info/?l=bugtraq&m=109225538901170&w=2Mailing List
- http://secunia.com/advisories/12276/Broken LinkPatchVendor Advisory
- http://security.gentoo.org/glsa/glsa-200408-13.xmlThird Party Advisory
- http://www.debian.org/security/2004/dsa-539Third Party Advisory
- http://www.kde.org/info/security/advisory-20040811-1.txtPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16963Third Party AdvisoryVDB Entry
FAQ
What is CVE-2004-0689?
CVE-2004-0689 is a vulnerability with a CVSS score of 7.1 (HIGH). KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
How severe is CVE-2004-0689?
CVE-2004-0689 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0689?
Check the references section above for vendor advisories and patch information. Affected products include: Kde Kde, Debian Debian Linux.