PT-2002-3142 · Kde+1 · Kde-I18N-Hebrew+57

Keith Winstein

+1

·

Published

1970-01-01

·

Updated

2016-10-18

·

CVE-2003-0204

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kde-i18n-Japanese version 2.2.2 kdemultimedia version 2.2.2 kde-i18n-Spanish version 2.2.2 kde-i18n-German version 2.2.2 kde-i18n-Chinese version 2.2.2 kde-i18n-Korean version 2.2.2 kde-i18n-Bulgarian version 2.2.2 kdevelop version 2.0.2 kde-i18n-Xhosa version 2.2.2 kdenetwork version 2.2.2 libkonq-dev (affected versions not specified) kdeadmin version 2.2.2 kde-i18n-Turkish version 2.2.2 kde-i18n-Chinese-Big5 (affected versions not specified) kde-i18n-Latvian version 2.2.2 kdebase-audiolibs (affected versions not specified) kdewallpapers (affected versions not specified) kde-i18n-Azerbaijani version 2.2.2 kde-i18n version 2.2.2 kde-i18n-Ukrainian version 2.2.2 kde-i18n-Finnish version 2.2.2 kde-i18n-Maltese version 2.2.2 kde-i18n-Italian version 2.2.2 kde-i18n-Hungarian version 2.2.2 kde-i18n-Portuguese version 2.2.2 kde-i18n-Slovak version 2.2.2 kde-i18n-Lithuanian version 2.2.2 kde-i18n-Afrikaans version 2.2.2 kdepim version 2.2.2 kdebase-libs (affected versions not specified) kde-i18n-Dutch version 2.2.2 kde-i18n-Norwegian version 2.2.2 kde-i18n-Norwegian-Nynorsk version 2.2.2 kde-i18n-British version 2.2.2 kde-i18n-Icelandic version 2.2.2 kdesupport version 2.2 kde-i18n-Tamil version 2.2.2 kde-i18n-Romanian version 2.2.2 kde-i18n-Slovenian version 2.2.2 kde-i18n-Danish version 2.2.2 kde-i18n-Hebrew version 2.2.2 libkonq3 (affected versions not specified) kde-i18n-Thai version 2.2.2 kde-i18n-Greek version 2.2.2 kdeutils version 2.2.2 kde-i18n-Czech version 2.2.2 kde-i18n-Serbian version 2.2.2 kde-i18n-Polish version 2.2.2 kdesdk version 2.2.2 kde-i18n-Brazil version 2.2.2 kde-i18n-Russian version 2.2.2 kde-i18n-French version 2.2.2 kde-i18n-Esperanto version 2.2.2 kdegraphics version 2.2.2 kde-i18n-Swedish version 2.2.2 kde-i18n-Estonian version 2.2.2 kdebindings version 2.2.2 KDE versions prior to 3.1.1
Description The issue is related to multiple vulnerabilities in various KDE packages, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. In particular, KDE 2 and KDE 3.1.1 and earlier 3.x versions are vulnerable to arbitrary command execution via PostScript or PDF files due to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.
Recommendations For each affected version, update to a version that is not vulnerable or apply the recommended patches. As a temporary workaround, consider disabling the use of PostScript and PDF files in the kghostview Ghostscript viewer until a patch is available. Restrict access to the vulnerable components to minimize the risk of exploitation. Avoid using the vulnerable packages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01783
BDU:2015-01786
BDU:2015-01787
BDU:2015-01790
BDU:2015-01791
BDU:2015-08025
BDU:2015-08033
BDU:2015-08035
BDU:2015-08038
BDU:2015-08040
BDU:2015-08042
BDU:2015-08043
BDU:2015-08045
BDU:2015-08047
BDU:2015-08049
BDU:2015-08051
BDU:2015-08052
BDU:2015-08054
BDU:2015-08056
BDU:2015-08057
BDU:2015-08058
BDU:2015-08059
BDU:2015-08060
BDU:2015-08061
BDU:2015-08062
BDU:2015-08063
BDU:2015-08064
BDU:2015-08065
BDU:2015-08066
BDU:2015-08067
BDU:2015-08068
BDU:2015-08069
BDU:2015-08070
BDU:2015-08071
BDU:2015-08072
BDU:2015-08073
BDU:2015-08074
BDU:2015-08075
BDU:2015-08076
BDU:2015-08077
BDU:2015-08078
BDU:2015-08079
BDU:2015-08080
BDU:2015-08081
BDU:2015-08082
BDU:2015-08083
BDU:2015-08084
BDU:2015-08085
BDU:2015-08086
BDU:2015-08087
BDU:2015-08093
BDU:2015-08095
BDU:2015-08098
BDU:2015-08100
BDU:2015-08102
BDU:2015-08103
BDU:2015-08105
CVE-2003-0204
DSA-284
DSA-293
DSA-296

Affected Products

Ghostscript
Kde-I18N
Kde-I18N-Afrikaans
Kde-I18N-Azerbaijani
Kde-I18N-Brazil
Kde-I18N-British
Kde-I18N-Bulgarian
Kde-I18N-Chinese
Kde-I18N-Chinese-Big5
Kde-I18N-Czech
Kde-I18N-Danish
Kde-I18N-Dutch
Kde-I18N-Esperanto
Kde-I18N-Estonian
Kde-I18N-Finnish
Kde-I18N-French
Kde-I18N-German
Kde-I18N-Greek
Kde-I18N-Hebrew
Kde-I18N-Hungarian
Kde-I18N-Icelandic
Kde-I18N-Italian
Kde-I18N-Japanese
Kde-I18N-Korean
Kde-I18N-Latvian
Kde-I18N-Lithuanian
Kde-I18N-Maltese
Kde-I18N-Norwegian
Kde-I18N-Norwegian-Nynorsk
Kde-I18N-Polish
Kde-I18N-Portuguese
Kde-I18N-Romanian
Kde-I18N-Russian
Kde-I18N-Serbian
Kde-I18N-Slovak
Kde-I18N-Slovenian
Kde-I18N-Spanish
Kde-I18N-Swedish
Kde-I18N-Tamil
Kde-I18N-Thai
Kde-I18N-Turkish
Kde-I18N-Ukrainian
Kde-I18N-Xhosa
Kdeadmin
Kdebase-Audiolibs
Kdebase-Libs
Kdebindings
Kdegraphics
Kdemultimedia
Kdenetwork
Kdepim
Kdesdk
Kdesupport
Kdeutils
Kdevelop
Kdewallpapers
Libkonq-Dev
Libkonq3