FreeBSD : kdewebdev -- kommander untrusted code execution vulnerability (91f1adc7-b3e9-11d9-a788-0001020eed82)

This script is Copyright (C) 2005-2013 Tenable Network Security, Inc.


Synopsis :

The remote FreeBSD host is missing a security-related update.

Description :

A KDE Security Advisory reports :

Kommander executes without user confirmation data files from possibly
untrusted locations. As they contain scripts, the user might
accidentally run arbitrary code.

Impact: Remotly supplied kommander files from untrusted sources are
executed without confirmation.

See also :

http://www.kde.org/info/security/advisory-20050420-1.txt
http://www.nessus.org/u?5eb75944

Solution :

Update the affected package.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)

Family: FreeBSD Local Security Checks

Nessus Plugin ID: 19032 (freebsd_pkg_91f1adc7b3e911d9a7880001020eed82.nasl)

Bugtraq ID:

CVE ID: CVE-2005-0754

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now