MDKSA-2006:106
- Package name
- mdkkdm
- Date
- 2006-06-15
- Advisory ID
- MDKSA-2006:106
- Affected versions
- CS3.0 i586 , CS3.0 x86_64
Problem description
A problem with how kdm manages the ~/.dmrc file was discovered by
Ludwig Nussel. By using a symlink attack, a local user could get kdm
to read arbitrary files on the system, including privileged system
files and those belonging to other users.
Mandriva's mdkkdm also suffers from this same problem and has been
patched to correct it. Only Corporate 3 is affected; in Mandriva Linux
2006, mdkkdm is in contribs.
Updated packages
CS3.0 i586
dd234f9831a30157879e25b29a14cf2f corporate/3.0/RPMS/mdkkdm-9.2-22.1.C30mdk.i586.rpm 043b4a58f3a101482a21afe8ca5d162b corporate/3.0/SRPMS/mdkkdm-9.2-22.1.C30mdk.src.rpm
CS3.0 x86_64
d1350d31ceb08dc68b1184469d23fea5 x86_64/corporate/3.0/RPMS/mdkkdm-9.2-22.1.C30mdk.x86_64.rpm 043b4a58f3a101482a21afe8ca5d162b x86_64/corporate/3.0/SRPMS/mdkkdm-9.2-22.1.C30mdk.src.rpm
