Package name
Advisory ID
Affected versions
CS3.0 i586 , CS3.0 x86_64

Problem description

A problem with how kdm manages the ~/.dmrc file was discovered by
Ludwig Nussel. By using a symlink attack, a local user could get kdm
to read arbitrary files on the system, including privileged system
files and those belonging to other users.

Mandriva's mdkkdm also suffers from this same problem and has been
patched to correct it. Only Corporate 3 is affected; in Mandriva Linux
2006, mdkkdm is in contribs.

Updated packages

CS3.0 i586

 dd234f9831a30157879e25b29a14cf2f  corporate/3.0/RPMS/mdkkdm-9.2-22.1.C30mdk.i586.rpm
 043b4a58f3a101482a21afe8ca5d162b  corporate/3.0/SRPMS/mdkkdm-9.2-22.1.C30mdk.src.rpm

CS3.0 x86_64

 d1350d31ceb08dc68b1184469d23fea5  x86_64/corporate/3.0/RPMS/mdkkdm-9.2-22.1.C30mdk.x86_64.rpm
 043b4a58f3a101482a21afe8ca5d162b  x86_64/corporate/3.0/SRPMS/mdkkdm-9.2-22.1.C30mdk.src.rpm