Mandrake Linux Security Advisory : kdelibs (MDKSA-2004:047)
High Nessus Plugin ID 14146
SynopsisThe remote Mandrake Linux host is missing one or more security updates.
DescriptionA vulnerability in the Opera web browser was identified by iDEFENSE;
the same type of vulnerability exists in KDE. The telnet, rlogin, ssh, and mailto URI handlers do not check for '-' at the beginning of the hostname passed, which makes it possible to pass an option to the programs started by the handlers. This can allow remote attackers to create or truncate arbitrary files.
The updated packages contain patches provided by the KDE team to fix this problem.
SolutionUpdate the affected packages.