PT-2002-1057 · Kde+1 · Kdeartwork+32

Published

2002-10-28

·

Updated

2008-09-05

·

CVE-2002-1224

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions KDE versions 3.0.1 through 3.0.3a kde-i18n-Catalan version 3.0.3 kcharselect version 3.0.3 kdelibs-sound version 2.2.2 kamera version 3.0.3 kde-i18n-Danish version 3.0.3 kaboodle version 3.0.3 kdenetwork version 2.2.2 kde-i18n-Czech version 3.0.3 kdesdk version 3.0.3 kde-i18n-Chinese-Big5 version 3.0.3 kde-i18n version 3.0.3 karm version 3.0.3 kdegraphics-devel version 2.2.2 kdeaddons version 3.0.3 kde-i18n-British version 3.0.3 kdegraphics version 3.0.3 kdeartwork version 3.0.3 kdepim version 3.0.3 kde-i18n-Brazil version 3.0.3 kdelibs-devel version 2.2.2 kdelibs version 2.2.2 kdelibs-sound-devel version 2.2.2 kdebindings version 3.0.3 kdenetwork-ppp version 2.2.2 kdenetwork version 3.0.3 kdeutils version 3.0.3 kcoloredit version 3.0.3 kdelibs version 3.0.3 kdebase version 3.0.3 kde-i18n-Afrikaans version 3.0.3 kdegraphics version 2.2.2 kde-i18n-Chinese version 3.0.3 kdemultimedia version 3.0.3 kdeadmin version 3.0.3 kdevelop version 2.1.3
Description The issue involves multiple vulnerabilities in various KDE packages for Red Hat Linux, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A directory traversal vulnerability in kpf for KDE 3.0.1 through 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.
Recommendations As a temporary workaround, consider disabling the vulnerable components until a patch is available. Restrict access to the vulnerable modules to minimize the risk of exploitation. Avoid using the modified icon parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08019
BDU:2015-08020
BDU:2015-08021
BDU:2015-08022
BDU:2015-08023
BDU:2015-08024
BDU:2015-08026
BDU:2015-08027
BDU:2015-08029
BDU:2015-08034
BDU:2015-08035
BDU:2015-08036
BDU:2015-08037
BDU:2015-08039
BDU:2015-08041
BDU:2015-08044
BDU:2015-08046
BDU:2015-08048
BDU:2015-08050
BDU:2015-08051
BDU:2015-08053
BDU:2015-08055
BDU:2015-08088
BDU:2015-08089
BDU:2015-08090
BDU:2015-08091
BDU:2015-08092
BDU:2015-08094
BDU:2015-08095
BDU:2015-08096
BDU:2015-08097
BDU:2015-08099
BDU:2015-08101
BDU:2015-08104
BDU:2015-08106
BDU:2015-08209
CVE-2002-1224

Affected Products

Kde
Red Hat
Kaboodle
Kamera
Karm
Kcharselect
Kcoloredit
Kde-I18N
Kde-I18N-Afrikaans
Kde-I18N-Brazil
Kde-I18N-British
Kde-I18N-Catalan
Kde-I18N-Chinese-Big5
Kde-I18N-Czech
Kde-I18N-Danish
Kdeaddons
Kdeadmin
Kdeartwork
Kdebase
Kdebindings
Kdegraphics
Kdegraphics-Devel
Kdelibs
Kdelibs-Devel
Kdelibs-Sound
Kdelibs-Sound-Devel
Kdemultimedia
Kdenetwork
Kdenetwork-Ppp
Kdepim
Kdesdk
Kdeutils
Kdevelop