Kommander: Insecure remote script execution
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200504-23 / Kommander |
| Release Date |
April 22, 2005 |
| Latest Revision |
May 20, 2005: 02 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| kde-base/kdewebdev |
<
3.3.2-r2 |
>=
3.3.2-r2 |
All supported architectures
|
Related bugreports:
#89092
Synopsis
Kommander executes remote scripts without confirmation, potentially
resulting in the execution of arbitrary code.
2.
Impact Information
Background
KDE is a feature-rich graphical desktop environment for Linux and
Unix-like Operating Systems. Kommander is a visual dialog editor and
interpreter for KDE applications, part of the kdewebdev package.
Description
Kommander executes data files from possibly untrusted locations without
user confirmation.
Impact
An attacker could exploit this to execute arbitrary code with the
permissions of the user running Kommander.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All kdewebdev users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=kde-base/kdewebdev-3.3.2-r2"
|
4.
References
|