CVE-2005-1920
KDE Security Advisory 2005-07-18.1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.
Las aplicaciones Kate y Kwrite en KDE 3.2.x hasta la 3.4.0 no fijan adecuadamente los permisos en los ficheros de backup, lo que podría permitir que usuarios locales, y posiblemente también remotos, obtengan información confidencial.
KDE Security Advisory: Kate / Kwrite create a file backup before saving a modified file. These backup files are created with default permissions, even if the original file had more strict permissions set. Depending on the system security settings, backup files might be readable by other users. All maintained versions of Kate and Kwrite as shipped with KDE 3.2.x up to including 3.4.0. KDE 3.1.x and older and KDE 3.4.1 and newer are not affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2005-06-08 CVE Reserved
- 2005-07-19 CVE Published
- 2024-08-07 CVE Updated
- 2025-07-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-281: Improper Preservation of Permissions
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=112171434023679&w=2 | Mailing List | |
http://secunia.com/advisories/16099 | Broken Link | |
http://secunia.com/advisories/23099 | Broken Link | |
http://securitytracker.com/id?1014512 | Broken Link | |
http://www.securityfocus.com/bid/14297 | Broken Link | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9434 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.kde.org/info/security/advisory-20050718-1.txt | 2024-01-25 |
URL | Date | SRC |
---|---|---|
http://security.gentoo.org/glsa/glsa-200611-21.xml | 2024-01-25 | |
http://www.debian.org/security/2005/dsa-804 | 2024-01-25 | |
http://www.novell.com/linux/security/advisories/2005_18_sr.html | 2024-01-25 | |
http://www.redhat.com/support/errata/RHSA-2005-612.html | 2024-01-25 | |
http://www.securityfocus.com/archive/1/427976/100/0/threaded | 2024-01-25 | |
https://access.redhat.com/security/cve/CVE-2005-1920 | 2005-07-27 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1617675 | 2005-07-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kde Search vendor "Kde" | Kde Search vendor "Kde" for product "Kde" | >= 3.2 <= 3.4.0 Search vendor "Kde" for product "Kde" and version " >= 3.2 <= 3.4.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 3.1 Search vendor "Debian" for product "Debian Linux" and version "3.1" | - |
Affected
|