Mandrake Linux Security Advisory : kdelibs (MDKSA-2004:047)

High Nessus Plugin ID 14146


The remote Mandrake Linux host is missing one or more security updates.


A vulnerability in the Opera web browser was identified by iDEFENSE;
the same type of vulnerability exists in KDE. The telnet, rlogin, ssh, and mailto URI handlers do not check for '-' at the beginning of the hostname passed, which makes it possible to pass an option to the programs started by the handlers. This can allow remote attackers to create or truncate arbitrary files.

The updated packages contain patches provided by the KDE team to fix this problem.


Update the affected packages.

See Also

Plugin Details

Severity: High

ID: 14146

File Name: mandrake_MDKSA-2004-047.nasl

Version: $Revision: 1.14 $

Type: local

Published: 2004/07/31

Modified: 2013/05/31

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:kdelibs-common, p-cpe:/a:mandriva:linux:lib64kdecore4, p-cpe:/a:mandriva:linux:lib64kdecore4-devel, p-cpe:/a:mandriva:linux:libkdecore4, p-cpe:/a:mandriva:linux:libkdecore4-devel, cpe:/o:mandrakesoft:mandrake_linux:10.0, cpe:/o:mandrakesoft:mandrake_linux:9.2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2004/05/18

Reference Information

CVE: CVE-2004-0411

MDKSA: 2004:047