Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Gentoo: 2003-01-18 Security Notice Regarding KDE 2.2.x Remote Vulnerability

gentoo
Calendar Grey January 20, 2003
Dist Gentoo Esm H88
- -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNC
In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution.

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200301-11
- --------------------------------------------------------------------
DATE    : 2003-01-18 02:47 UTC

- --------------------------------------------------------------------
From advisory:
"In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution.
These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage or files on a network filesystem or other untrusted source.
By carefully crafting such data an attacker might be able to execute arbitary commands on a vulnerable sytem using the victim's account and privileges.
The KDE Project is aware of several possible exploits of these vulnerabilities and is releasing this advisory with patches to correct the issues. The patches also provide better safe guards and check data ...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
important
Lowest
Low
Medium
High
Critical

PACKAGE : kde-2.2.x
SUMMARY : multiple vulnerabilites in KDE
EXPLOIT : remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here