PT-2002-1057 · Kde+1 · Kdeartwork+32
Publicado
2002-10-28
·
Atualizado
2008-09-05
·
CVE-2002-1224
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
KDE versions 3.0.1 through 3.0.3a
kde-i18n-Catalan version 3.0.3
kcharselect version 3.0.3
kdelibs-sound version 2.2.2
kamera version 3.0.3
kde-i18n-Danish version 3.0.3
kaboodle version 3.0.3
kdenetwork version 2.2.2
kde-i18n-Czech version 3.0.3
kdesdk version 3.0.3
kde-i18n-Chinese-Big5 version 3.0.3
kde-i18n version 3.0.3
karm version 3.0.3
kdegraphics-devel version 2.2.2
kdeaddons version 3.0.3
kde-i18n-British version 3.0.3
kdegraphics version 3.0.3
kdeartwork version 3.0.3
kdepim version 3.0.3
kde-i18n-Brazil version 3.0.3
kdelibs-devel version 2.2.2
kdelibs version 2.2.2
kdelibs-sound-devel version 2.2.2
kdebindings version 3.0.3
kdenetwork-ppp version 2.2.2
kdenetwork version 3.0.3
kdeutils version 3.0.3
kcoloredit version 3.0.3
kdelibs version 3.0.3
kdebase version 3.0.3
kde-i18n-Afrikaans version 3.0.3
kdegraphics version 2.2.2
kde-i18n-Chinese version 3.0.3
kdemultimedia version 3.0.3
kdeadmin version 3.0.3
kdevelop version 2.1.3
Description
The issue involves multiple vulnerabilities in various KDE packages for Red Hat Linux, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A directory traversal vulnerability in kpf for KDE 3.0.1 through 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.
Recommendations
As a temporary workaround, consider disabling the vulnerable components until a patch is available.
Restrict access to the vulnerable modules to minimize the risk of exploitation.
Avoid using the modified icon parameter in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kde
Red Hat
Kaboodle
Kamera
Karm
Kcharselect
Kcoloredit
Kde-I18N
Kde-I18N-Afrikaans
Kde-I18N-Brazil
Kde-I18N-British
Kde-I18N-Catalan
Kde-I18N-Chinese-Big5
Kde-I18N-Czech
Kde-I18N-Danish
Kdeaddons
Kdeadmin
Kdeartwork
Kdebase
Kdebindings
Kdegraphics
Kdegraphics-Devel
Kdelibs
Kdelibs-Devel
Kdelibs-Sound
Kdelibs-Sound-Devel
Kdemultimedia
Kdenetwork
Kdenetwork-Ppp
Kdepim
Kdesdk
Kdeutils
Kdevelop