Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

KDE Postscript/PDF File Processing Arbitrary Command Execution Vulnerability

Solution:
Red Hat has released a security advisory (RHSA-2003:002-01), which addresses the issue. Please see the attached advisory for details on obtaining fixes.

Red Hat has also released an advisory and fixes for Red Hat Enterprise Linux. Fixes for Enterprise Linux may be obtained through the Red Hat Network.

KDE 3.0.5b and 3.1.1a are not vulnerable to this issue.

Mandrake Linux has released an advisory (MDKSA-2003:049) and fixes. Information about obtaining and applying fixes are available in the referenced advisory.

Gentoo Linux has released an updated advisory (200304-05.1) for kde 2.x systems. Affected users are advised to upgrade systems by issuing the following commands:

emerge sync
emerge \=kde-base/kdebase-2.2.2-r5
emerge \=kde-base/kdelibs-2.2.2a-r2
emerge \=kde-base/kdegraphics-2.2.2-r2
emerge clean

Gentoo Linux has released an advisory. Users who have installed kde-base/kde are advised to upgrade to kde-3.1.1a or kde-3.0.5b by issuing the following commands:

emerge sync
emerge kde OR \=kde-base/kde-3.0.5b
emerge clean

Gentoo Linux has released a new advisory (200304-05) for kde 2.x systems. Affected users are advised to upgrade systems by issuing the following commands:

emerge sync
emerge \=kde-base/kdebase-2.2.2-r5
emerge \=kde-base/kdelibs-2.2.2a-r1
emerge \=kde-base/kdegraphics-2.2.2-r2
emerge clean

Debian has released an advisory DSA 284-1. Information about obtaining and applying fixes are available in the referenced advisory. Users of the apt-get system can upgrade their systems by issuing the following commands:

apt-get update
apt-get upgrade

Sorcerer Linux has released an advisory. Affected users are advised to issue the following commands to upgrade their systems:

augur synch && augur newer && augur update

Gentoo Linux has released a new advisory for kde 3.1.1a systems. It is recommended that all Gentoo Linux users who are running kde-base/kdegraphics upgrade to kdegraphics-3.1.1a-r1 as follows:

emerge sync
emerge kdegraphics
emerge clean

Slackware Linux has released an advisory. Users of KDE are advised to upgrade systems to KDE 3.1.1a by issuing the following commands as the root user:

upgradepkg *.tgz

Debian has released a security advisory (DSA 293-1) which contains fixes addressing this issue. Further information regarding how to obtain and apply fixes can be found in the attached advisory.

SuSE has released an advisory SuSE-SA:2003:026. SuSE has advised affected users to update systems using YaST2. Further information is available in the referenced advisory.

Debian has released a new security advisory (DSA 296-1). Information about obtaining and applying fixes can be found in the referenced advisory. Users of the apt-get system are advised to issue the following commands to update affected systems:

apt-get update
apt-get upgrade

Sun has released updates for Sun Linux 5.0.5.

Conectiva has released an advisory (CLA-2003:668) to address this issue. Please see the attached advisory for details on obtaining and applying fixes manually. Users can also upgrade using the following apt commands:

apt-get update
apt-get upgrade

Conectiva has released an advisory CLA-2003:747, including fixes to address this and other issues.

SUSE has released an advisory SuSE-SA:2004:009 with additional fixes to address this and other issues. Please see the advisory for more information.

Fixes available:


KDE KDE 2.2.2

KDE KDE 3.0

KDE KDE 3.0.1

KDE KDE 3.0.2

KDE KDE 3.0.3

KDE KDE 3.0.3 a

KDE KDE 3.0.4

KDE KDE 3.0.5 a

KDE KDE 3.0.5

KDE KDE 3.1

KDE KDE 3.1.1







 

Privacy Statement
Copyright 2008, SecurityFocus