CVE-2004-0689 describes a local privilege escalation vulnerability in KDE prior to version 3.3.0, affecting Debian Linux and KDE distributions. The flaw stems from improper handling of symbolic links pointing to "stale" locations, allowing a local attacker to create or truncate arbitrary files. With a CVSS score of 7.1 (HIGH), this vulnerability has a low attack complexity and requires local user privileges, potentially leading to high integrity and availability impacts. Despite its age and high community discussion (10 mentions), there is no evidence of active exploitation, nor are there known public exploits in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3CPE matchmatch criteria | cpe:2.3:o:kde:kde:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.