Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA 296-1 Critical Threat From kdebase Remote Code Execution

debian
Calendar Grey April 30, 2003
Debian Logo
- -------------------------------------------------------------------------- Debian Security Advisor
The KDE team discoverd a vulnerability in the way KDE uses Ghostscript software for processing of PostScript (PS) and PDF files.

Summary

The KDE team discoverd a vulnerability in the way KDE uses Ghostscript
software for processing of PostScript (PS) and PDF files. An attacker
could provide a malicious PostScript or PDF file via mail or websites
that could lead to executing arbitrary commands under the privileges
of the user viewing the file or when the browser generates a directory
listing with thumbnails.

For the stable distribution (woody) this problem has been fixed in
version 2.2.2-14.4 of kdebase and associated packages.

The old stable distribution (potato) is not affected since it does not
contain KDE.

For the unstable distribution (sid) this problem will be fixed soon.

For the unofficial backport of KDE 3.1.1 to woody by Ralf Nolden on
download.kde.org, this problem has been fixed in version 3.1.1-0woody3
of kdebase. Using the normal backport line for apt-get you will get
the update:

deb stable main

We recommend that you upgrade your kdebase and associated packages.


Upgrade Instructions
- --------------------

wget url
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: kdebase

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here