Summary
The remote host is missing an update to kdelibs
announced via advisory DSA 804-1.
KDE developers have reported a vulnerability in the backup file handling of Kate and Kwrite. The backup files are created with default permissions, even if the original file had more strict permissions set. This could disclose information unintendedly.
Solution
For the stable distribution (sarge) this problem has been fixed in version 3.3.2-6.2.
For the unstable distribution (sid) these problems have been fixed in version 3.4.1-1.
We recommend that you upgrade your kate package.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20804-1
Severity
Classification
-
CVE CVE-2005-1920 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities