|
Family: Debian Local Security Checks --> Category: infos
[DSA296] DSA-296-1 kdebase Vulnerability Scan
Vulnerability Scan Summary DSA-296-1 kdebase
Detailed Explanation for this Vulnerability Test
The KDE team discovered a vulnerability in the way KDE uses Ghostscript
software for processing of PostScript (PS) and PDF files. A possible hacker
could provide a malicious PostScript or PDF file via mail or websites
that could lead to executing arbitrary commands under the rights
of the user viewing the file or when the browser generates a directory
listing with thumbnails.
For the stable distribution (woody) this problem has been fixed in
version 2.2.2-14.4 of kdebase and associated packages.
The old stable distribution (potato) is not affected since it does not
contain KDE.
For the unstable distribution (sid) this problem will be fixed soon.
For the unofficial backport of KDE 3.1.1 to woody by Ralf Nolden on
download.kde.org, this problem has been fixed in version 3.1.1-0woody3
of kdebase. Using the normal backport line for apt-get you will get
the update:
deb http://download.kde.org/stable/latest/Debian stable main
We recommend that you upgrade your kdebase and associated packages.
Solution : http://www.debian.org/security/2003/dsa-296
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|