NASLDB: Mandrake Linux Security Advisory : kde (MDKSA-2003:004-1)
General
ID: 13989
Name: Mandrake Linux Security Advisory : kde (MDKSA-2003:004-1)
Summary: Checks rpm output for the updated packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS Temporal Vector: –
Port: 0
Family: Mandriva Local Security Checks
Type: Local
Description
Multiple instances of improperly quoted shell command execution exist
in KDE 2.x up to and including KDE 3.0.5. KDE fails to properly quote
parameters of instructions passed to the shell for execution. These
parameters may contain data such as filenames, URLs, email address,
and so forth; this data may be provided remotely to a victim via
email, web pages, files on a network filesystem, or other untrusted
sources.
It is possible for arbitrary command execution on a vulnerable system
with the privileges of the victim’s account.
The code audit by the KDE team resulted in patches for KDE 2.2.2 and
KDE 3; version 3.0.5a was released and the KDE team encourages the
upgrade. The listed KDE2 packages have the KDE team’s patches applied
to provide the fixed code.
Update :
The SRPM for the new arts for Mandrake Linux 9.0 was not linked into
the updates tree. This has been corrected.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2002-1393
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: 2003/01/17
Plugin Release: 2004/07/31
Plugin
Version: 1.13
Filename: mandrake_MDKSA-2003-004.nasl
Filesize: 6489 bytes
MD5 Hash: 6615a2d256b857fbe5130df846d2ca38
Identification: Host/local_checks_enabled
Require Keys: Host/local_checks_enabled", "Host/cpu", "Host/Mandrake/release", "Host/Mandrake/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2004-2012 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













