KDE Parameter Quoting Shell Command Execution Vulnerability Solution:
Red Hat has released a security advisory (RHSA-2003:002-01), which addresses the issue. Please see the attached advisory for details on obtaining fixes.
Gentoo Linux has released an advisory. Users who have installed kde-base/kde-3.0.4 and earlier are advised to upgrade their systems by issuing the following commands:
emerge rsync
emerge kde
emerge clean
Gentoo Linux has released a new advisory. Users who have installed kde-base/kde-2.2.x are advised to upgrade their systems to kde*-2.2.2-{r1,r2,r4} by issuing the following commands:
emerge sync
emerge -u \=kde-base/kde-2.2*
emerge clean
Debian has released advisories (DSA 234-1, DSA 235-1, DSA 236-1, DSA 237-1, DSA 238-1, DSA 239-1, DSA 240-1, DSA 241-1, DSA 242-1, DSA 243-1) which address this issue.
Debian users using the apt-get package manager are advised to upgrade their systems by issuing the following commands:
apt-get update or
apt-get upgrade
Please see the attached Debian advisories for details on obtaining and applying fixes.
Conectiva has released a security advisory (CLA-2003:569) which addresses the issue. Please see the attached advisory for details on obtaining fixes.
Fixes have been made available by the vendor. See attached reference.
Sun has released updates for Sun Linux 5.0.5.
Fixes available:
KDE KDE 2.2.2
KDE KDE 3.0.3