Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian 3.0 DSA 293-1 Severe: Kdelibs Remote Command Execution

debian
Calendar Grey April 23, 2003
Debian Logo
Debian Advisory DSA 293-1 reports a critical remote execution flaw in Kdelibs due to Ghostscript usage.
The KDE team discoverd a vulnerability in the way KDE uses Ghostscript software for processing of PostScript (PS) and PDF files.

Summary

The KDE team discoverd a vulnerability in the way KDE uses Ghostscript
software for processing of PostScript (PS) and PDF files. An attacker
could provide a malicious PostScript or PDF file via mail or websites
that could lead to executing arbitrary commands under the privileges
of the user viewing the file or when the browser generates a directory
listing with thumbnails.

For the stable distribution (woody) this problem has been fixed in
version 2.2.2-13.woody.7 of kdelibs and associated packages.

The old stable distribution (potato) is not affected since it does not
contain KDE.

For the unstable distribution (sid) this problem will be fixed soon.

For the unofficial backport of KDE 3.1.1 to woody by Ralf Nolden on
download.kde.org, this problem has been fixed in version 3.1.1-0woody3
of kdelibs. Using the normal backport line for apt-get you will get
the update:

deb stable main

We recommend that you upgrade your kdelibs and associated packages.


Upgrade Instructions
- --------------------

wget url
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: kdelibs

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here