Nessus Plugin #18126

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[GLSA-200504-23] Kommander: Insecure remote script execution

Family:
Gentoo Local Security Checks
Category:
infos
Copyright:
(C) 2005 Michel Arboi
Summary:
Kommander: Insecure remote script execution
Version:
$Revision: 1.1 $
Cve_id:
CAN-2005-0754
Bugtraq_id:
-
Xrefs:
GLSA:200504-23
Description:
The remote host is affected by the vulnerability described in GLSA-200504-23
(Kommander: Insecure remote script execution)


Kommander executes data files from possibly untrusted locations
without user confirmation.

Impact

An attacker could exploit this to execute arbitrary code with the
permissions of the user running Kommander.

Workaround

There is no known workaround at this time.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0754
http://www.kde.org/info/security/advisory-20050420-1.txt


Solution:
All kdewebdev users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=kde-base/kdewebdev-3.3.2-r1"


Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.