Mandrake Linux Security Advisory : kdelibs (MDKSA-2004:047)

High Nessus Plugin ID 14146

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

A vulnerability in the Opera web browser was identified by iDEFENSE;
the same type of vulnerability exists in KDE. The telnet, rlogin, ssh, and mailto URI handlers do not check for '-' at the beginning of the hostname passed, which makes it possible to pass an option to the programs started by the handlers. This can allow remote attackers to create or truncate arbitrary files.

The updated packages contain patches provided by the KDE team to fix this problem.

Solution

Update the affected packages.

See Also

https://www.securityfocus.com/archive/1/363225

Plugin Details

Severity: High

ID: 14146

File Name: mandrake_MDKSA-2004-047.nasl

Version: 1.16

Type: local

Published: 2004/07/31

Updated: 2018/11/15

Dependencies: 12634

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:kdelibs-common, p-cpe:/a:mandriva:linux:lib64kdecore4, p-cpe:/a:mandriva:linux:lib64kdecore4-devel, p-cpe:/a:mandriva:linux:libkdecore4, p-cpe:/a:mandriva:linux:libkdecore4-devel, cpe:/o:mandrakesoft:mandrake_linux:10.0, cpe:/o:mandrakesoft:mandrake_linux:9.2

Patch Publication Date: 2004/05/18

Reference Information

CVE: CVE-2004-0411

MDKSA: 2004:047