CVE-2022-24986

HIGH

KDE KCron < 21.12.2 - Unauthorized Command Execution via Temporary File Reuse

Title source: llm
STIX 2.1

Description

KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.

References (2)

Core 2
Core References
Product x_refsource_misc
https://apps.kde.org/kcron/
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2022/02/25/3

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 24.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362 CWE-668
Status published
Products (1)
kde/kcron < 21.12.2
Published Feb 26, 2022
Tracked Since Feb 18, 2026