CVE-2005-3149

Publication date 5 October 2005

Last updated 17 July 2025


Ubuntu priority

Uim 0.4.x before 0.4.9.1 and 0.5.0 and earlier does not properly handle the LIBUIM_VANILLA environment variable when a suid or sgid application is linked to libuim, such as immodule for Qt, which allows local users to gain privileges.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
uim 7.04 feisty
Fixed 1.0.0-1ubuntu1
6.10 edgy
Fixed 1.0.0-1ubuntu1
6.06 LTS dapper
Fixed 1.0.0-1ubuntu1