Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian 3.0: DSA-204-1 critical: Kdelibs Remote Command Execution

debian
Calendar Grey December 5, 2002
Debian Logo
Immediate alert issued for kdelibs security flaws, exposing Debian systems to potential unauthorized command execution risks via remote access protocols.
There is a vulnerability in the support for various network protocols via the KIO The implementation of the rlogin and protocol allows a carefully crafted URL in an HTML page, HTML...

Summary

The KDE team has discovered a vulnerability in the support for various
network protocols via the KIO The implementation of the rlogin and
protocol allows a carefully crafted URL in an HTML page, HTML email or
other KIO-enabled application to execute arbitrary commands on the
system using the victim's account on the vulnerable machine.

This problem has been fixed by disabling rlogin and telnet in version
2.2.2-13.woody.5 for the current stable distribution (woody) and in
version 2.2.2-14.1 for the unstable distribution (sid). The old
stable distribution (potato) is not affected since it doesn't contain
KDE.

This problem has been fixed by disabling rlogin and telnet in version
2.2.2-13.woody.5 for the current stable distribution (woody). The old
stable distribution (potato) is not affected since it doesn't contain
KDE. A correction for the package in the unstable distribution (sid)
is not yet available.

We recommend that you upgrade your kdelibs3 package immediately.

wget url
will fetch the...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: kdelibs

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here