Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 172527 - kde-base/kdelibs KDE ioslave PASV port scanning vulnerability (CVE-2007-1564)
Summary: kde-base/kdelibs KDE ioslave PASV port scanning vulnerability (CVE-2007-1564)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://www.kde.org/info/security/advi...
Whiteboard: B4 [noglsa] jaervosz
Keywords:
: 174812 (view as bug list)
Depends on:
Blocks: 172746
  Show dependency tree
 
Reported: 2007-03-28 07:58 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2007-04-16 16:33 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-03-28 07:58:19 UTC
KDE Security Advisory: KDE ioslave PASV port scanning vulnerability
Original Release Date: 2007-03-26
URL: http://www.kde.org/info/security/advisory-20070326-1.txt

0. References
        CVE-2007-1564


1. Systems affected:

        KDE up to including KDE version 3.5.6.


2. Overview:

        The KDE FTP ioslave parses the host address in the PASV response
        of a FTP server response. mark from bindshell.net pointed
        out that this could be exploited via JavaScript for automated
        port scanning. It was not possible to demonstrate the
        vulnerability via JavaScript with Konqueror from KDE 3.5.x.
        However, other scenarios are possible.


3. Impact:

        Untrusted sites or sites that allow Javascript injection
        could cause Konqueror or other web browsers based on KHTML
        to perform port scanning.


4. Solution:

        Source code patches have been made available which fix these
        vulnerabilities. Contact your OS vendor / binary package provider
        for information about how to obtain updated binary packages.


5. Patch:

        Patch for KDE 3.5.x and newer is available from
        ftp://ftp.kde.org/pub/kde/security_patches :

        62872147c2d369feb3d9077e9b32b03d  CVE-2007-1564-kdelibs-3.5.6.diff

        Patch for KDE 3.4.x and newer is available from
        ftp://ftp.kde.org/pub/kde/security_patches :

        13535c902a6b3223005adfc1fccdd32f  CVE-2007-1564-kdelibs-3.4.3.diff
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-03-28 07:59:19 UTC
KDE please advise and bump as necessary. Note: I didn't check which package actually include this.
Comment 2 Carsten Lohrke (RETIRED) gentoo-dev 2007-03-31 14:07:41 UTC
Actually this is "sort of" a dupe of bug 169529, just that one went completely wrong, as it included only half of the fix and also only kdelibs-3.5.5 has been adressed...

I'll commit a new 3.5.6 revision including some other patches as well, soon.


kdelibs-3.5.5-r10 needs to go stable. Arch teams, pretty please...
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-03-31 15:14:44 UTC
Thx Carlo.
Comment 4 Raúl Porcel (RETIRED) gentoo-dev 2007-03-31 18:08:11 UTC
ia64 + x86 stable.
Comment 5 Jeroen Roovers (RETIRED) gentoo-dev 2007-04-01 21:15:23 UTC
Stable for HPPA.
Comment 6 Markus Rothe (RETIRED) gentoo-dev 2007-04-02 18:03:17 UTC
ppc64 stable
Comment 7 Gustavo Zacarias (RETIRED) gentoo-dev 2007-04-03 13:01:58 UTC
sparc stable.
Comment 8 Tobias Scherbaum (RETIRED) gentoo-dev 2007-04-03 19:37:16 UTC
ppc stable
Comment 9 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2007-04-05 09:21:55 UTC
alpha done
Comment 10 Marcus D. Hanwell (RETIRED) gentoo-dev 2007-04-09 19:36:14 UTC
Stable on amd64.
Comment 11 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-04-11 10:06:53 UTC
This one is ready for GLSA decision. I tend to vote NO.
Comment 12 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-04-11 10:17:42 UTC
voting no.
Comment 13 Matthias Geerdsen (RETIRED) gentoo-dev 2007-04-12 15:23:01 UTC
voting no
Comment 14 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-04-12 16:29:22 UTC
2+ NO votes -> Closing with NO GLSA. Feel free to reopen if you disagree.
Comment 15 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-04-16 16:33:05 UTC
*** Bug 174812 has been marked as a duplicate of this bug. ***