CVE-2004-0689

HIGH

KDE < 3.3.0 - Arbitrary File Creation or Truncation via Stale Symbolic Link Handling

Title source: llm
STIX 2.1

Description

KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.

References (8)

Core 8
Core References
Broken Link vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000864
Broken Link, Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12276/
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16963
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-539
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200408-13.xml
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109225538901170&w=2
Patch, Vendor Advisory x_refsource_confirm
http://www.kde.org/info/security/advisory-20040811-1.txt

Scores

CVSS v3 7.1
EPSS 0.0003
EPSS Percentile 8.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-59
Status published
Products (2)
debian/debian_linux 3.0
kde/kde < 3.3
Published Sep 28, 2004
Tracked Since Feb 18, 2026