PT-2002-3155 · Kde · Kde-I18N-Hebrew+64

Publicado

1970-01-01

·

Atualizado

2016-10-18

·

CVE-2002-1393

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions KDE versions 2.2.2 through 3.0.5 kde-i18n-Japanese-2.2.2 version 2.2.2 kdemultimedia-2.2.2 version 2.2.2 lskat version (affected versions not specified) artsbuilder version (affected versions not specified) kde-i18n-Spanish-2.2.2 version 2.2.2 kde-i18n-German-2.2.2 version 2.2.2 kde-i18n-Chinese-2.2.2 version 2.2.2 kde-i18n-Korean-2.2.2 version 2.2.2 kde-i18n-Bulgarian-2.2.2 version 2.2.2 kdesdk version (affected versions not specified) kdevelop-2.0.2 version 2.0.2 kde-i18n-Xhosa-2.2.2 version 2.2.2 kdenetwork-2.2.2 version 2.2.2 libarts-mpeglib version (affected versions not specified) kdeadmin-2.2.2 version 2.2.2 poxml version (affected versions not specified) kde-i18n-Turkish-2.2.2 version 2.2.2 kde-i18n-2.2.2 version 2.2.2 kdepim-dev version (affected versions not specified) kde-i18n-Ukrainian-2.2.2 version 2.2.2 kde-i18n-Maltese-2.2.2 version 2.2.2 kde-i18n-Finnish-2.2.2 version 2.2.2 kde-i18n-Italian-2.2.2 version 2.2.2 kde-i18n-Hungarian-2.2.2 version 2.2.2 kde-i18n-Slovak-2.2.2 version 2.2.2 kde-i18n-Lithuanian-2.2.2 version 2.2.2 kde-i18n-Portuguese-2.2.2 version 2.2.2 kde-i18n-Afrikaans-2.2.2 version 2.2.2 kdepim-2.2.2 version 2.2.2 kde-i18n-Dutch-2.2.2 version 2.2.2 kde-i18n-Norwegian-2.2.2 version 2.2.2 kde-i18n-Norwegian-Nynorsk-2.2.2 version 2.2.2 kdepalettes version (affected versions not specified) kde-i18n-Icelandic-2.2.2 version 2.2.2 kde-i18n-British-2.2.2 version 2.2.2 kdesupport-2.2 version 2.2 kde-i18n-Tamil-2.2.2 version 2.2.2 kde-i18n-Romanian-2.2.2 version 2.2.2 kdepim-libs version (affected versions not specified) kde-i18n-Slovenian-2.2.2 version 2.2.2 kde-i18n-Danish-2.2.2 version 2.2.2 kde-i18n-Hebrew-2.2.2 version 2.2.2 kdf version (affected versions not specified) klpq version (affected versions not specified) klprfax version (affected versions not specified) kde-i18n-Thai-2.2.2 version 2.2.2 kde-i18n-Greek-2.2.2 version 2.2.2 kdemultimedia-dev version (affected versions not specified) kdeutils-2.2.2 version 2.2.2 kde-i18n-Polish-2.2.2 version 2.2.2 kde-i18n-Czech-2.2.2 version 2.2.2 kde-i18n-Serbian-2.2.2 version 2.2.2 kde-i18n-Brazil-2.2.2 version 2.2.2 kdesdk-2.2.2 version 2.2.2 kde-i18n-Russian-2.2.2 version 2.2.2 kde-i18n-French-2.2.2 version 2.2.2 kde-i18n-Esperanto-2.2.2 version 2.2.2 kdesdk-doc version (affected versions not specified) khexedit version (affected versions not specified) kdecarddecks version (affected versions not specified) kdegraphics-2.2.2 version 2.2.2 kde-i18n-Swedish-2.2.2 version 2.2.2 kde-i18n-Estonian-2.2.2 version 2.2.2 kdebindings-2.2.2 version 2.2.2 kuser version (affected versions not specified)
Description Multiple vulnerabilities have been discovered in various KDE packages, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities are caused by the failure to quote certain parameters that are inserted into a shell command, allowing remote attackers to execute arbitrary commands via URLs, filenames, or e-mail addresses.
Recommendations For KDE versions 2.2.2 through 3.0.5, update to a version later than 3.0.5. For kde-i18n-Japanese-2.2.2 version 2.2.2, update to a version later than 2.2.2. For kdemultimedia-2.2.2 version 2.2.2, update to a version later than 2.2.2. For lskat, artsbuilder, kdesdk, kdevelop-2.0.2, kdenetwork-2.2.2, libarts-mpeglib, kdeadmin-2.2.2, poxml, kdepim-dev, kdepim-libs, kdf, klpq, klprfax, kdemultimedia-dev, kdeutils-2.2.2, kdesdk-doc, khexedit, kdecarddecks, and kuser, update to the latest version available. For all other affected packages, update to a version later than the specified version. As a temporary workaround, consider disabling the execution of shell commands with unquoted parameters until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-02668
BDU:2015-02669
BDU:2015-02670
BDU:2015-02671
BDU:2015-02967
BDU:2015-02968
BDU:2015-03445
BDU:2015-03446
BDU:2015-03447
BDU:2015-03448
BDU:2015-04066
BDU:2015-04067
BDU:2015-04068
BDU:2015-04069
BDU:2015-04070
BDU:2015-04071
BDU:2015-04072
BDU:2015-04079
BDU:2015-04080
BDU:2015-04081
BDU:2015-04082
BDU:2015-08025
BDU:2015-08033
BDU:2015-08035
BDU:2015-08038
BDU:2015-08040
BDU:2015-08042
BDU:2015-08043
BDU:2015-08045
BDU:2015-08047
BDU:2015-08049
BDU:2015-08051
BDU:2015-08052
BDU:2015-08054
BDU:2015-08056
BDU:2015-08057
BDU:2015-08058
BDU:2015-08059
BDU:2015-08060
BDU:2015-08061
BDU:2015-08062
BDU:2015-08063
BDU:2015-08064
BDU:2015-08065
BDU:2015-08066
BDU:2015-08067
BDU:2015-08068
BDU:2015-08069
BDU:2015-08070
BDU:2015-08071
BDU:2015-08072
BDU:2015-08073
BDU:2015-08074
BDU:2015-08075
BDU:2015-08076
BDU:2015-08077
BDU:2015-08078
BDU:2015-08079
BDU:2015-08080
BDU:2015-08081
BDU:2015-08082
BDU:2015-08083
BDU:2015-08084
BDU:2015-08085
BDU:2015-08086
BDU:2015-08087
BDU:2015-08093
BDU:2015-08095
BDU:2015-08098
BDU:2015-08100
BDU:2015-08102
BDU:2015-08103
BDU:2015-08105
CVE-2002-1393
DSA-234
DSA-235
DSA-236
DSA-237
DSA-238
DSA-239
DSA-240
DSA-241
DSA-242
DSA-243

Produtos afetados

Kde
Artsbuilder
Kde-I18N
Kde-I18N-Afrikaans
Kde-I18N-Brazil
Kde-I18N-British
Kde-I18N-Bulgarian
Kde-I18N-Chinese
Kde-I18N-Czech
Kde-I18N-Danish
Kde-I18N-Dutch
Kde-I18N-Esperanto
Kde-I18N-Estonian
Kde-I18N-Finnish
Kde-I18N-French
Kde-I18N-German
Kde-I18N-Greek
Kde-I18N-Hebrew
Kde-I18N-Hungarian
Kde-I18N-Icelandic
Kde-I18N-Italian
Kde-I18N-Japanese
Kde-I18N-Korean
Kde-I18N-Lithuanian
Kde-I18N-Maltese
Kde-I18N-Norwegian
Kde-I18N-Norwegian-Nynorsk
Kde-I18N-Polish
Kde-I18N-Portuguese
Kde-I18N-Romanian
Kde-I18N-Russian
Kde-I18N-Serbian
Kde-I18N-Slovak
Kde-I18N-Slovenian
Kde-I18N-Spanish
Kde-I18N-Swedish
Kde-I18N-Tamil
Kde-I18N-Thai
Kde-I18N-Turkish
Kde-I18N-Ukrainian
Kde-I18N-Xhosa
Kdeadmin
Kdebindings
Kdecarddecks
Kdegraphics
Kdemultimedia
Kdemultimedia-Dev
Kdenetwork
Kdepalettes
Kdepim
Kdepim-Dev
Kdepim-Libs
Kdesdk
Kdesdk-Doc
Kdesupport
Kdeutils
Kdevelop
Kdf
Khexedit
Klpq
Klprfax
Kuser
Libarts-Mpeglib
Lskat
Poxml