Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 51274 - KDE Security Advisory: URI Handler Vulnerabilities
Summary: KDE Security Advisory: URI Handler Vulnerabilities
Status: RESOLVED DUPLICATE of bug 51276
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High critical (vote)
Assignee: Gentoo Security
URL: http://www.kde.org/info/security/advi...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-05-17 05:39 UTC by Eldad Zack (RETIRED)
Modified: 2011-10-30 22:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Eldad Zack (RETIRED) gentoo-dev 2004-05-17 05:39:36 UTC
1. Systems affected:

        All versions of KDE up to KDE 3.2.2 inclusive. 


2. Overview:

        iDEFENSE identified a vulnerability in the Opera Web Browser
        that could allow remote attackers to create or truncate
        arbitrary files. The KDE team has found that similar
        vulnerabilities exists in KDE.

        The telnet, rlogin, ssh and mailto URI handlers in KDE do not
        check for '-' at the beginning of the hostname passed, which
        makes it possible to pass an option to the programs started
        by the handlers.

        The Common Vulnerabilities and Exposures project (cve.mitre.org)
        has assigned the name CAN-2004-0411 to this issue.
Comment 1 Caleb Tennis (RETIRED) gentoo-dev 2004-05-17 17:38:35 UTC

*** This bug has been marked as a duplicate of 51276 ***