VYPR
High severity7.8OSV Advisory· Published May 8, 2018· Updated Jun 17, 2026

CVE-2018-10380

CVE-2018-10380

Description

kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Range: v4.96.0, v4.97.0, v4.98.0, …
  • cpe:2.3:a:kde:plasma:*:*:*:*:*:*:*:*
    Range: <5.12.6
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OpenSUSE/Leap2 versions
    cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*
  • KDE/KWalletllm-fuzzy
    Range: <5.12.6

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.