KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.
References
Link Resource
http://www.openwall.com/lists/oss-security/2022/02/25/3 Mailing List Third Party Advisory
https://apps.kde.org/kcron/ Product
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-02-26T04:06:21

Updated: 2022-02-26T04:06:21

Reserved: 2022-02-14T00:00:00


Link: CVE-2022-24986

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-26T05:15:08.343

Modified: 2023-08-08T14:22:24.967


Link: CVE-2022-24986

JSON object: View

cve-icon Redhat Information

No data.