// For flags

CVE-2018-10361

 

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on the local system to gain root privileges. The attack occurs when one user (who has an unprivileged account but is also able to authenticate as root) writes a text file using Kate into a directory owned by a another unprivileged user. The latter unprivileged user conducts a symlink attack to achieve privilege escalation.

Se ha descubierto un problema en KTextEditor, desde la versión 5.34.0 hasta la 5.45.0. La gestión insegura de archivos temporales en el servicio kauth_ktexteditor_helper de KTextEditor (tal y como se emplea en el editor de texto de Kate) puede permitir que otros usuarios sin privilegios en el sistema local obtengan privilegios root. El ataque ocurre cuando un usuario (que tiene una cuenta no privilegiada pero también puede autenticarse como root) escribe un archivo de texto con Kate en un directorio propiedad de otro usuario sin privilegios. Este último usuario sin privilegios lleva a cabo un ataque de vínculo simbólico para lograr el escalado de privilegios.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-04-24 CVE Reserved
  • 2018-04-25 CVE Published
  • 2023-04-19 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Kde
Search vendor "Kde"
Ktexteditor
Search vendor "Kde" for product "Ktexteditor"
>= 5.34.0 <= 5.45.0
Search vendor "Kde" for product "Ktexteditor" and version " >= 5.34.0 <= 5.45.0"
-
Affected