PT-2004-1057 · Kde+1 · Kdebase-Devel+3

Publicado

2004-12-10

·

Atualizado

2017-10-11

·

CVE-2004-1165

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Konqueror version 3.3.1 kdebase-devel versions 2.2.2 through 3.1.3 kdebase versions 2.2.2 through 3.1.3
Description The issue allows remote attackers to execute arbitrary commands, potentially leading to a breach of confidentiality, integrity, and availability of protected information. This can be achieved by exploiting multiple vulnerabilities in the affected packages, which can be done remotely. For example, in Konqueror, an ftp:// URL containing a URL-encoded newline ("%0a") before an FTP command can cause the commands to be inserted into the resulting FTP session.
Recommendations For Konqueror version 3.3.1, consider disabling the ability to handle ftp:// URLs until a patch is available. For kdebase-devel versions 2.2.2 through 3.1.3, restrict access to sensitive information and functions to minimize the risk of exploitation. For kdebase versions 2.2.2 through 3.1.3, avoid using potentially vulnerable components or functions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06209
BDU:2015-06210
BDU:2015-06211
BDU:2015-06212
CVE-2004-1165
DSA-631-1
RHSA-2005:009
RHSA-2005:065
RHSA-2005_009
RHSA-2005_065

Produtos afetados

Konqueror
Red Hat
Kdebase
Kdebase-Devel