Nessus Plugin #15121

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[DSA284] DSA-284-1 kdegraphics

Family:
Debian Local Security Checks
Category:
infos
Copyright:
This script is (C) 2004 Michel Arboi
Summary:
DSA-284-1 kdegraphics
Version:
$Revision: 1.4 $
Cve_id:
CAN-2003-0204
Bugtraq_id:
7318
Xrefs:
DSA:284
Description:

The KDE team discovered a vulnerability in the way KDE uses Ghostscript
software for processing of PostScript (PS) and PDF files. An attacker
could provide a malicious PostScript or PDF file via mail or websites
that could lead to executing arbitrary commands under the privileges
of the user viewing the file or when the browser generates a directory
listing with thumbnails.
For the stable distribution (woody) this problem has been fixed in
version 2.2.2-6.11 of kdegraphics and associated packages.
The old stable distribution (potato) is not affected since it does not
contain KDE.
For the unstable distribution (sid) this problem will be fixed soon.
For the unofficial backport of KDE 3.1.1 to woody by Ralf Nolden on
download.kde.org, this problem has been fixed in version 3.1.1-0woody2
of kdegraphics. Using the normal backport line for apt-get you will
get the update:
deb http://download.kde.org/stable/latest/Debian stable main
We recommend that you upgrade your kdegraphics and associated packages.


Solution : http://www.debian.org/security/2003/dsa-284
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.