HIGH
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack
Published May 8, 2018
7.8
HIGHCVSS 3.0
EPSS 0.43%
Description
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
7.8 HIGH NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
7.2 HIGH NVD
AV:L/AC:L/Au:N/C:C/I:C/A:C
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
0.43% 0.00427
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
EPSS probability 0.00427
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.43% (0.00427) | 34.64th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.43% (0.00427) | 36.58th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00042) | 5.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.03% (0.01034) | 20.32th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.89% (0.00888) | 25.41th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.89% (0.00888) | 0.00th | v1 |
Weaknesses (1)
References (7)
- https://bugzilla.suse.com/show_bug.cgi?id=1090863 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://commits.kde.org/kwallet-pam/01d4143fda5bddb6dca37b23304dc239a5fb38b5 x_refsource_CONFIRMPatchVendor Advisory
- https://commits.kde.org/kwallet-pam/2134dec85ce19d6378d03cddfae9e5e464cb24c0 x_refsource_CONFIRMPatchVendor Advisory
- https://commits.kde.org/kwallet-pam/802f305d81f8771c4f4a8bd7fd0e368ffc6f9b3b x_refsource_CONFIRMPatchVendor Advisory
- https://commits.kde.org/kwallet-pam/99abc7fde21f40cc6da5feb6ee766cc46fcca1f8 x_refsource_CONFIRMPatchVendor Advisory
- https://www.debian.org/security/2018/dsa-4200 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.kde.org/info/security/advisory-20180503-1.txt x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1090863 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://commits.kde.org/kwallet-pam/01d4143fda5bddb6dca37b23304dc239a5fb38b5 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://commits.kde.org/kwallet-pam/2134dec85ce19d6378d03cddfae9e5e464cb24c0 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://commits.kde.org/kwallet-pam/802f305d81f8771c4f4a8bd7fd0e368ffc6f9b3b | x_refsource_CONFIRMPatchVendor Advisory | |
| https://commits.kde.org/kwallet-pam/99abc7fde21f40cc6da5feb6ee766cc46fcca1f8 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://www.debian.org/security/2018/dsa-4200 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.kde.org/info/security/advisory-20180503-1.txt | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 8, 2018
Updated Aug 5, 2024
Reserved Apr 25, 2018
Link CVE-2018-10380
CISA Vulnrichment
Updated n/a