Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: kde-2.2.x
Date: Sat, 18 Jan 2003 03:00:56
Message-Id: 20030118024752.518F833BB7@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200301-11
6 - - --------------------------------------------------------------------
7
8 PACKAGE : kde-2.2.x
9 SUMMARY : multiple vulnerabilites in KDE
10 DATE : 2003-01-18 02:47 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 - From advisory:
16
17 "In some instances KDE fails to properly quote parameters of
18 instructions passed to a command shell for execution.
19
20 These parameters may incorporate data such as URLs, filenames and
21 e-mail addresses, and this data may be provided remotely to a victim
22 in an e-mail, a webpage or files on a network filesystem or other
23 untrusted source.
24
25 By carefully crafting such data an attacker might be able to
26 execute arbitary commands on a vulnerable sytem using the victim's
27 account and privileges.
28
29 The KDE Project is aware of several possible exploits of these
30 vulnerabilities and is releasing this advisory with patches to
31 correct the issues. The patches also provide better safe guards and
32 check data from untrusted sources more strictly in multiple places."
33
34 Read the full advisory at
35 http://www.kde.org/info/security/advisory-20021220-1.txt
36
37 INFORMATION REGARDING OTHER ARCHITECTURES THAN X86
38
39 Updated kde-2.2.2 ebuilds are currently only marked stable for x86.
40 If you have succesfully compiled, merged and used kde-2.2.2 on any other
41 architecture than x86 please report this to kde@g.o.
42
43 SOLUTION
44
45 It is recommended that all Gentoo Linux users who are running
46 kde-base/kde-2.2.x upgrade to kde*-2.2.2-{r1,r2,r4} as follows:
47
48 emerge sync
49 emerge -u \=kde-base/kde-2.2*
50 emerge clean
51
52 - - --------------------------------------------------------------------
53 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
54 kde@g.o
55 - - --------------------------------------------------------------------
56 -----BEGIN PGP SIGNATURE-----
57 Version: GnuPG v1.2.1 (GNU/Linux)
58
59 iD8DBQE+KMBWfT7nyhUpoZMRAs9DAJ9uFIDTzigQcPFyIJ7IKBfwxnnuqQCgo54W
60 uqM1nqqXfCxsSd03+DGtEYU=
61 =UdE9
62 -----END PGP SIGNATURE-----