Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA 284-1 Critical: kdegraphics Remote Execution Threat

debian
Calendar Grey April 14, 2003
Debian Logo
Critical security alert for kdegraphics in Debian, highlighting risks of remote execution via Ghostscript flaws.
The KDE team discoverd a vulnerability in the way KDE uses Ghostscript software for processing of PostScript (PS) and PDF files.

Summary

The KDE team discoverd a vulnerability in the way KDE uses Ghostscript
software for processing of PostScript (PS) and PDF files. An attacker
could provide a malicious PostScript or PDF file via mail or websites
that could lead to executing arbitrary commands under the privileges
of the user viewing the file or when the browser generates a directory
listing with thumbnails.

For the stable distribution (woody) this problem has been fixed in
version 2.2.2-6.11 of kdegraphics and associated packages.

The old stable distribution (potato) is not affected since it does not
contain KDE.

For the unstable distribution (sid) this problem will be fixed soon.

For the unofficial backport of KDE 3.1.1 to woody by Ralf Nolden on
download.kde.org, this problem has been fixed in version 3.1.1-0woody2
of kdegraphics. Using the normal backport line for apt-get you will
get the update:

deb stable main

We recommend that you upgrade your kdegraphics and associated packages.


Upgrade Instructions
- --------------------

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: kdegraphics

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here