Language Selection

English French German Italian Portuguese Spanish

KDE Kommander Arbitrary Code Execution Vulnerability

Filed under
KDE
Security

Eckhart Wörner has reported a vulnerability in KDE, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a design error in Kommander, as it executes data files containing scripts without user confirmation.

Successful exploitation allows execution of arbitrary code on a user's system via a malicious kommander file.

The vulnerability affects Quanta 3.1.x and KDE versions 3.2 through 3.4.0.

Solution:
Apply patches.

Patch for KDE 3.4.0:
ftp://ftp.kde.org/pub/kde/securi...t-3.4.0-kdewebdev-kommander.diff
c388b21d91c8326fc9757cd8786713db

Patch for KDE 3.3.2:
ftp://ftp.kde.org/pub/kde/securi...t-3.3.2-kdewebdev-kommander.diff
d210c07121c1ba3a97660a6e166738e6

Original Advisory:
KDE:
http://www.kde.org/info/security/advisory-20050420-1.txt

Source & live links.

More in Tux Machines

Git 2.2.1 Released To Fix Critical Security Issue

Today's Git vulnerability affects those using the Git client on case-insensitive file-systems. On case-insensitive platforms like Windows and OS X, committing to .Git/config could overwrite the user's .git/config and could lead to arbitrary code execution. Fortunately with most Phoronix readers out there running Linux, this isn't an issue thanks to case-sensitive file-systems. Read more

Ubuntu 15.04 Alpha 1 For Its Various Flavors

While Ubuntu itself no longer puts out alpha/beta releases in favor of just testing out the daily Live ISOs, the various Ubuntu flavors still participating in the traditional release process have done their first alpha releases this afternoon for Ubuntu 15.04. Read more

Robolinux 7.7.1 LXDE Runs Windows Apps with Stealth VM

Robolinux 7.7.1, a fast and easy-to-use Linux distribution based on Debian has just received a new desktop environment, LXDE, making this the third second flavor of the distribution. Read more

Jolla's Sailfish OS Update 10 Is Now Available

The tenth update to Jolla's Sailfish mobile operating system is now available. This update is version 1.1.1.26 and is codenamed Vaarainjärvi. This latest update to Jolla's Sailfish OS includes the device lock now supporting alpha-numeric codes, copy-paste support between Android and native Sailfish apps, Mail app improvements, new overlays for maps, search improvements, unification to the accounts framework, new MMS settings, UI improvements, and an assortment of other improvements. Read more