SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#982616

KDE2 kdesu 'keep password' option does not verify socket listener potentially exposing su password

Overview

kdesu is a interactive interface to the substitute user (su) command for the KDE environment. To pass authentication information, it creates a file that may be read by unauthorized users.

I. Description

kdesu communicates with su using a socket, implemented as a file in /tmp with a predictable name. In this file is placed authenticating information for the effective user that the kdesu user wishes to become (often root).

II. Impact

By using a symbolic link attack, an attacker may be able to capture usernames and passwords.

III. Solution

Apply vendor patches; see the Systems Affected section below.

Creating files in /tmp with appropriate names may block the symbolic link attack, but it may also prevent kdesu from operating properly. It will not be a robust fix.

Systems Affected

VendorStatusDate NotifiedDate Updated
CalderaVulnerable17-May-2001
ConectivaVulnerable17-May-2001
MandrakeSoftVulnerable17-May-2001
RedHatVulnerable17-May-2001
SuSEVulnerable17-May-2001

References

http://www.calderasystems.com/support/security/advisories/CSSA-2001-005.0.txt
http://www.securityfocus.com/bid/2669
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-046.php3?dis=8.0
http://www.linuxsecurity.com/advisories/redhat_advisory-1335.html
http://www.linuxsecurity.com/advisories/other_advisory-1119.html
http://www.linuxsecurity.com/advisories/suse_advisory-1113.html

Credit

Initial information on this vulnerability came from a statement by Caldera Systems.

This document was last modified by Tim Shimeall.

Other Information

Date Public:2001-01-23
Date First Published:2001-05-17
Date Last Updated:2001-08-01
CERT Advisory: 
CVE-ID(s):CAN-2001-0178
NVD-ID(s):CAN-2001-0178
US-CERT Technical Alerts: 
Severity Metric:8.10
Document Revision:11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2001 Carnegie Mellon University
Disclaimers and copyright information
Get a PDF Reader