Unrated severityNVD Advisory· Published May 2, 2005· Updated Apr 16, 2026
CVE-2005-0205
CVE-2005-0205
Description
KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.
Affected products
7- cpe:2.3:o:bernd_wuebben:kppp:2.1.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- distro.conectiva.com.br/atualizacoes/nvdPatch
- www.debian.org/security/2005/dsa-692nvdPatchVendor Advisory
- www.idefense.com/application/poi/displaynvdPatchVendor Advisory
- www.kde.org/info/security/advisory-20050228-1.txtnvdPatchVendor Advisory
- www.redhat.com/support/errata/RHSA-2005-175.htmlnvdPatchVendor Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9596nvd
News mentions
0No linked articles in our index yet.