PT-2004-1057 · Kde+1 · Kdebase-Devel+3

Published

2004-12-10

·

Updated

2017-10-11

·

CVE-2004-1165

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Konqueror version 3.3.1 kdebase-devel versions 2.2.2 through 3.1.3 kdebase versions 2.2.2 through 3.1.3
Description The issue allows remote attackers to execute arbitrary commands, potentially leading to a breach of confidentiality, integrity, and availability of protected information. This can be achieved by exploiting multiple vulnerabilities in the affected packages, which can be done remotely. For example, in Konqueror, an ftp:// URL containing a URL-encoded newline ("%0a") before an FTP command can cause the commands to be inserted into the resulting FTP session.
Recommendations For Konqueror version 3.3.1, consider disabling the ability to handle ftp:// URLs until a patch is available. For kdebase-devel versions 2.2.2 through 3.1.3, restrict access to sensitive information and functions to minimize the risk of exploitation. For kdebase versions 2.2.2 through 3.1.3, avoid using potentially vulnerable components or functions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06209
BDU:2015-06210
BDU:2015-06211
BDU:2015-06212
CVE-2004-1165
DSA-631-1
RHSA-2005:009
RHSA-2005:065
RHSA-2005_009
RHSA-2005_065

Affected Products

Konqueror
Red Hat
Kdebase
Kdebase-Devel