Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.52673
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-115-1 (kdewebdev)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to kdewebdev
announced via advisory USN-115-1.

A security issue affects the following Ubuntu releases:

Ubuntu 5.04 (Hoary Hedgehog)

The following packages are affected: kommander

Details follow:

Eckhart Wörner discovered that Kommander opens files from remote and
possibly untrusted locations without user confirmation. Since
Kommander files can contain scripts, this would allow an attacker to
execute arbitrary code with the privileges of the user opening the
file.

The updated Kommander will not automatically open files from remote
locations, and files which do not end with .kmdr any more.

Solution:
The problem can be corrected by upgrading the affected package to
version 4:3.4.0-0ubuntu2.2. In general, a standard system upgrade is
sufficient to effect the necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-115-1

Risk factor : High

CVSS Score:
7.5

Cross-Ref: BugTraq ID: 13313
Common Vulnerability Exposure (CVE) ID: CVE-2005-0754
http://www.securityfocus.com/bid/13313
Bugtraq: 20050422 [KDE Security Advisory]: Kommander untrusted code execution (Google Search)
http://marc.info/?l=bugtraq&m=111419664411051&w=2
http://secunia.com/advisories/15060
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.