PT-2002-1023 · Kde+4 · Kde-I18N-Danish+29

Publicado

2002-09-23

·

Atualizado

2016-10-18

·

CVE-2002-0838

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gv version 3.5.8 and earlier kdelibs version 2.2.2 and earlier kdelibs-sound version 2.2.2 and earlier kdegraphics version 2.2.2 and earlier kde-i18n-Catalan version 3.0.3 and earlier kde-i18n-Danish version 3.0.3 and earlier kde-i18n-Czech version 3.0.3 and earlier kde-i18n-Chinese-Big5 version 3.0.3 and earlier kde-i18n-British version 3.0.3 and earlier kde-i18n-Brazil version 3.0.3 and earlier kde-i18n-Afrikaans version 3.0.3 and earlier kde-i18n-Chinese version 3.0.3 and earlier qt version 3.0.5 and earlier kamera version 3.0.3 and earlier kaboodle version 3.0.3 and earlier kdenetwork version 2.2.2 and earlier kdesdk version 3.0.3 and earlier kdeartwork version 3.0.3 and earlier kdepim version 3.0.3 and earlier kdelibs-devel version 2.2.2 and earlier kdelibs-sound-devel version 2.2.2 and earlier kdebindings version 3.0.3 and earlier kdenetwork-ppp version 2.2.2 and earlier kdenetwork version 3.0.3 and earlier kdeutils version 3.0.3 and earlier kcoloredit version 3.0.3 and earlier kdemultimedia version 3.0.3 and earlier kdeadmin version 3.0.3 and earlier kdevelop version 2.1.3 and earlier gnome-gv version (affected versions not specified)
Description The issue is related to multiple vulnerabilities in various packages of the Red Hat Linux operating system, including qt, kde, and gnome. These vulnerabilities can be exploited remotely, leading to a breach of confidentiality, integrity, and availability of protected information. The exploitation can be carried out through malicious PDF or PostScript files processed by an unsafe call to sscanf.
Recommendations As a temporary workaround, consider disabling the sscanf function until a patch is available. Restrict access to the vulnerable packages to minimize the risk of exploitation. Avoid using the vulnerable packages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03459
BDU:2015-07799
BDU:2015-08019
BDU:2015-08020
BDU:2015-08021
BDU:2015-08022
BDU:2015-08023
BDU:2015-08024
BDU:2015-08026
BDU:2015-08027
BDU:2015-08029
BDU:2015-08034
BDU:2015-08035
BDU:2015-08036
BDU:2015-08037
BDU:2015-08039
BDU:2015-08041
BDU:2015-08044
BDU:2015-08046
BDU:2015-08048
BDU:2015-08050
BDU:2015-08051
BDU:2015-08053
BDU:2015-08055
BDU:2015-08088
BDU:2015-08089
BDU:2015-08090
BDU:2015-08091
BDU:2015-08092
BDU:2015-08094
BDU:2015-08095
BDU:2015-08096
BDU:2015-08097
BDU:2015-08099
BDU:2015-08101
BDU:2015-08104
BDU:2015-08106
BDU:2015-08209
CVE-2002-0838
DSA-176
DSA-179
DSA-182

Produtos afetados

Red Hat
Gnome-Gv
Gv
Kaboodle
Kamera
Kcoloredit
Kde-I18N-Afrikaans
Kde-I18N-Brazil
Kde-I18N-British
Kde-I18N-Catalan
Kde-I18N-Chinese
Kde-I18N-Chinese-Big5
Kde-I18N-Czech
Kde-I18N-Danish
Kdeadmin
Kdeartwork
Kdebindings
Kdegraphics
Kdelibs
Kdelibs-Devel
Kdelibs-Sound
Kdelibs-Sound-Devel
Kdemultimedia
Kdenetwork
Kdenetwork-Ppp
Kdepim
Kdesdk
Kdeutils
Kdevelop
Qt