KDE - command parameter quoting problems
| Package(s): | kde | CVE #(s): | CAN-2002-1393 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | December 24, 2002 | Updated: | February 21, 2003 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | In some instances, KDE (versions 2 and 3) fails to properly quote parameters of instructions
passed to a command shell for execution.
These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage or files on a network filesystem or other untrusted source. By carefully crafting such data an attacker might be able to execute arbitary commands on a vulnerable sytem using the victim's account and privileges. See this announcement for more details. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
