Unrated severityNVD Advisory· Published Oct 5, 2005· Updated Apr 16, 2026
CVE-2005-3149
CVE-2005-3149
Description
Uim 0.4.x before 0.4.9.1 and 0.5.0 and earlier does not properly handle the LIBUIM_VANILLA environment variable when a suid or sgid application is linked to libuim, such as immodule for Qt, which allows local users to gain privileges.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- bugs.debian.org/cgi-bin/bugreport.cginvdPatch
- lists.freedesktop.org/pipermail/uim/2005-September/001346.htmlnvdPatch
- lists.freedesktop.org/pipermail/uim/2005-September/001347.htmlnvdPatch
- secunia.com/advisories/17043nvdPatchVendor Advisory
- www.gentoo.org/security/en/glsa/glsa-200510-03.xmlnvdPatchVendor Advisory
- secunia.com/advisories/17058nvd
- secunia.com/advisories/17572nvd
- securitytracker.com/idnvd
- www.debian.org/security/2005/dsa-895nvd
- www.securityfocus.com/bid/15007nvd
- www.vupen.com/english/advisories/2005/1946nvd
- www.vupen.com/english/advisories/2005/1947nvd
News mentions
0No linked articles in our index yet.