KDE KCron through 21.12.2 uses a temporary file in /tmp...
High severity
Unreviewed
Published
Feb 27, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Feb 26, 2022
Published to the GitHub Advisory Database
Feb 27, 2022
Last updated
Feb 3, 2023
KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.
References