CVE-2022-24986

Name
CVE-2022-24986
Description
KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Mailing List http://www.openwall.com/lists/oss-security/2022/02/25/3
Product https://apps.kde.org/kcron/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:kde:kcron:*:*:*:*:*:*:*:* kcron >= None <= 21.12.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
kcron 3.15-community 21.08.3-r0 Bart Ribbers <bribbers@disroot.org> possibly vulnerable