Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51207
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2003:003
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2003:003.

A security issue has been found in KDE. This errata provides updates which
resolve these issues.

KDE is a graphical desktop environment for the X Window System.

KDE fails in multiple places to properly quote URLs and filenames
before passing them to a command shell. This could allow remote
attackers to execute arbitrary commands through carefully crafted URLs,
filenames, or email addresses.

Users of KDE are advised to install the updated packages which contain
backported patches to correct this issue.

Please note that for the Itanium (IA64) architecture only, this update also
fixes several other vulnerabilities. Details concerning these
vulnerabilities can be found in advisory RHSA-2002:221 and correspond to
CVE names CVE-2002-0970, CVE-2002-1151, CVE-2002-1247, and CVE-2002-1306.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2003-003.html
http://www.kde.org/info/security/advisory-20021220-1.txt

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-1393
BugTraq ID: 6462
http://www.securityfocus.com/bid/6462
Bugtraq: 20021221 KDE Security Advisory: Multiple vulnerabilities in KDE (Google Search)
http://marc.info/?l=bugtraq&m=104049734911544&w=2
Bugtraq: 20021222 GLSA: kde-3.0.x (Google Search)
http://marc.info/?l=bugtraq&m=104066520330397&w=2
Conectiva Linux advisory: CLA-2003:569
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000569
Debian Security Information: DSA-234 (Google Search)
http://www.debian.org/security/2003/dsa-234
Debian Security Information: DSA-235 (Google Search)
http://www.debian.org/security/2003/dsa-235
Debian Security Information: DSA-236 (Google Search)
http://www.debian.org/security/2003/dsa-236
Debian Security Information: DSA-237 (Google Search)
http://www.debian.org/security/2003/dsa-237
Debian Security Information: DSA-238 (Google Search)
http://www.debian.org/security/2003/dsa-238
Debian Security Information: DSA-239 (Google Search)
http://www.debian.org/security/2003/dsa-239
Debian Security Information: DSA-240 (Google Search)
http://www.debian.org/security/2003/dsa-240
Debian Security Information: DSA-241 (Google Search)
http://www.debian.org/security/2003/dsa-241
Debian Security Information: DSA-242 (Google Search)
http://www.debian.org/security/2003/dsa-242
Debian Security Information: DSA-243 (Google Search)
http://www.debian.org/security/2003/dsa-243
http://www.mandriva.com/security/advisories?name=MDKSA-2003:004
http://www.redhat.com/support/errata/RHSA-2003-002.html
http://www.redhat.com/support/errata/RHSA-2003-003.html
http://secunia.com/advisories/8067
http://secunia.com/advisories/8103
Common Vulnerability Exposure (CVE) ID: CVE-2002-0970
BugTraq ID: 5410
http://www.securityfocus.com/bid/5410
Bugtraq: 20020812 Re: IE SSL Vulnerability (Konqueror affected too) (Google Search)
http://marc.info/?l=bugtraq&m=102918241005893&w=2
Bugtraq: 20020818 KDE Security Advisory: Konqueror SSL vulnerability (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2002-08/0170.html
Caldera Security Advisory: CSSA-2002-047.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-047.0.txt
Conectiva Linux advisory: CLA-2002:519
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000519
Debian Security Information: DSA-155 (Google Search)
http://www.debian.org/security/2002/dsa-155
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:058
http://www.redhat.com/support/errata/RHSA-2002-220.html
http://www.redhat.com/support/errata/RHSA-2002-221.html
XForce ISS Database: ssl-ca-certificate-spoofing(9776)
https://exchange.xforce.ibmcloud.com/vulnerabilities/9776
Common Vulnerability Exposure (CVE) ID: CVE-2002-1151
BugTraq ID: 5689
http://www.securityfocus.com/bid/5689
Bugtraq: 20020910 KDE Security Advisory: Konqueror Cross Site Scripting Vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=103175850925395&w=2
Conectiva Linux advisory: CLA-2002:525
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000525
Debian Security Information: DSA-167 (Google Search)
http://www.debian.org/security/2002/dsa-167
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-064.php
http://www.osvdb.org/7867
http://www.iss.net/security_center/static/10039.php
Common Vulnerability Exposure (CVE) ID: CVE-2002-1247
BugTraq ID: 6157
http://www.securityfocus.com/bid/6157
Bugtraq: 20021111 iDEFENSE Security Advisory 11.11.02: Buffer Overflow in KDE resLISa (Google Search)
http://marc.info/?l=bugtraq&m=103704823501757&w=2
Bugtraq: 20021112 KDE Security Advisory: resLISa / LISa Vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=103712329102632&w=2
Bugtraq: 20021114 GLSA: kdelibs (Google Search)
http://marc.info/?l=bugtraq&m=103728981029342&w=2
Computer Incident Advisory Center Bulletin: N-020
http://www.ciac.org/ciac/bulletins/n-020.shtml
Debian Security Information: DSA-193 (Google Search)
http://www.debian.org/security/2002/dsa-193
http://www.mandriva.com/security/advisories?name=MDKSA-2002:080
http://www.idefense.com/advisory/11.11.02.txt
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0068.html
http://www.iss.net/security_center/static/10592.php
Common Vulnerability Exposure (CVE) ID: CVE-2002-1306
Debian Security Information: DSA-214 (Google Search)
http://www.debian.org/security/2002/dsa-214
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-080.php
SuSE Security Announcement: SuSE-SA:2002:042 (Google Search)
http://www.novell.com/linux/security/advisories/2002_042_kdenetwork.html
http://www.iss.net/security_center/static/10598.php
http://www.iss.net/security_center/static/10597.php
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.