CERT home
vulnerabilities & fixesevaluations & practicesresearch & analysistraining & education
homesearchFAQsite indexcontact
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

Vulnerability Note VU#982616

KDE2 kdesu 'keep password' option does not verify socket listener potentially exposing su password

Overview

kdesu is a interactive interface to the substitute user (su) command for the KDE environment. To pass authentication information, it creates a file that may be read by unauthorized users.

I. Description

kdesu communicates with su using a socket, implemented as a file in /tmp with a predictable name. In this file is placed authenticating information for the effective user that the kdesu user wishes to become (often root).

II. Impact

By using a symbolic link attack, an attacker may be able to capture usernames and passwords.

III. Solution

Apply vendor patches; see the Systems Affected section below.

Creating files in /tmp with appropriate names may block the symbolic link attack, but it may also prevent kdesu from operating properly. It will not be a robust fix.

Systems Affected

VendorStatusDate Updated
CalderaVulnerable17-May-2001
ConectivaVulnerable17-May-2001
MandrakeSoftVulnerable17-May-2001
RedHatVulnerable17-May-2001
SuSEVulnerable17-May-2001

References


http://www.calderasystems.com/support/security/advisories/CSSA-2001-005.0.txt
http://www.securityfocus.com/bid/2669
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-046.php3?dis=8.0
http://www.linuxsecurity.com/advisories/redhat_advisory-1335.html
http://www.linuxsecurity.com/advisories/other_advisory-1119.html
http://www.linuxsecurity.com/advisories/suse_advisory-1113.html

Credit

Initial information on this vulnerability came from a statement by Caldera Systems.

This document was last modified by Tim Shimeall.

Other Information

Date Public01/23/2001
Date First Published05/17/2001 02:37:34 PM
Date Last Updated08/01/2001
CERT Advisory 
CVE NameCAN-2001-0178
Metric8.10
Document Revision11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Copyright 2001 Carnegie Mellon University