KDE Postscript/PDF文件处理任意命令执行漏洞

admin 2022-07-18 14:46:01 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

KDE Postscript/PDF文件处理任意命令执行漏洞

  • CNNVD编号:CNNVD-200305-005
  • 危害等级: 高危
  • CVE编号: CVE-2003-0204
  • 漏洞类型: 其他
  • 发布时间: 2003-04-10
  • 威胁类型: 远程
  • 更新时间: 2005-10-20
  • 厂        商: kde
  • 漏洞来源: KDE security advis...

漏洞简介

KDE使用Ghostscript软件处理PS和PDF文件。 KDE在处理畸形PDF和PS文件时存在漏洞,远程攻击者可以利用这个漏洞可能以用户进程权限执行任意命令。 攻击者可以准备恶意PostScript或PDF文件,构建恶意WEB页诱使用户点击或EMAIL发送给用户打开,可导致嵌入的命令以用户进程权限执行。目前没有提供详细漏洞细节。

漏洞公告

厂商补丁: Debian ------ http://www.debian.org/security/2003/dsa-284 KDE --- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

KDE KDE 2.2.2:

KDE Patch post-2.2.2-kdebase-thumbnail.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdebase-thumbnail.diff

KDE Patch post-2.2.2-kdegraphics-kdvi.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdegraphics-kdvi.diff

KDE Patch post-2.2.2-kdegraphics-kghostview-2.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdegraphics-kghostview-2.diff

KDE Patch post-2.2.2-kdelibs-kimgio.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdelibs-kimgio.diff

KDE KDE 3.0:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.1:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.2:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.3 a:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.3:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.4:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.5 a:

KDE Patch post-3.0.5a-kdebase-thumbnail.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdebase-thumbnail.diff

KDE Patch post-3.0.5a-kdegraphics-kdvi.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdegraphics-kdvi.diff

KDE Patch post-3.0.5a-kdegraphics-kghostview.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdegraphics-kghostview.diff

KDE Patch post-3.0.5a-kdelibs-kimgio.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdelibs-kimgio.diff

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/

KDE KDE 3.1:

KDE Upgrade KDE 3.1.1a

http://download.kde.org/stable/3.1.1a/

KDE KDE 3.1.1:

KDE Patch post-3.1.1-kdebase-thumbnail.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdebase-thumbnail.diff

KDE Patch post-3.1.1-kdegraphics-kdvi.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdegraphics-kdvi.diff

KDE Patch post-3.1.1-kdegraphics-kghostview.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdegraphics-kghostview.diff

KDE Patch post-3.1.1-kdelibs-kimgio.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdelibs-kimgio.diff

KDE Upgrade KDE 3.1.1a

http://download.kde.org/stable/3.1.1a/ MandrakeSoft ------------ MandrakeSoft已经为此发布了一个安全公告(MDKSA-2003:049)以及相应补丁:

MDKSA-2003:049:Updated kde3 packages fix arbitrary command execution

链接: http://www.linux-mandrake.com/en/security/2003/2003-049.php

补丁下载:

Updated Packages:

Corporate Server 2.1:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdebase-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdebase-devel-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdebase-nsplugins-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdelibs-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdelibs-devel-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdegraphics-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdegraphics-devel-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/kdebase-3.0.5a-1.2mdk.src.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/kdelibs-3.0.5a-1.2mdk.src.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/kdegraphics-3.0.5a-1.2mdk.src.rpm

Mandrake Linux 9.0:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdebase-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdebase-devel-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdebase-nsplugins-3.0.5a-1.2mdk.i586.rpm

参考网址

来源: www.kde.org 链接:http://www.kde.org/info/security/advisory-20030409-1.txt 来源: DEBIAN 名称: DSA-284 链接:http://www.debian.org/security/2003/dsa-284 来源: REDHAT 名称: RHSA-2003:002 链接:http://www.redhat.com/support/errata/RHSA-2003-002.HTML 来源: DEBIAN 名称: DSA-296 链接:http://www.debian.org/security/2003/dsa-296 来源: DEBIAN 名称: DSA-293 链接:http://www.debian.org/security/2003/dsa-293 来源: bugs.kde.org 链接:http://bugs.kde.org/show_bug.cgi?id=56808 来源: bugs.kde.org 链接:http://bugs.kde.org/show_bug.cgi?id=53343 来源: MANDRAKE 名称: MDKSA-2003:049 链接:http://www.mandriva.com/security/advisories?name=MDKSA-2003:049 来源: BUGTRAQ 名称: 20030414 GLSA: kde-2.x (200304-05.1) 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105034222521369&w=2 来源: BUGTRAQ 名称: 20030412 [Sorcerer-spells] KDE-SORCERER2003-04-12 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105017403010459&w=2 来源: BUGTRAQ 名称: 20030411 GLSA: kde-2.x (200304-05) 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105012994719099&w=2 来源: BUGTRAQ 名称: 20030410 GLSA: kde-3.x (200304-04) 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105001557020141&w=2 来源: CONECTIVA 名称: CLA-2003:747 链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000747 来源: CONECTIVA 名称: CLA-2003:668 链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000668

受影响实体

  • Kde Kde:2.0  
  • Kde Kde:2.0.1  
  • Kde Kde:2.1  
  • Kde Kde:2.1.1  
  • Kde Kde:2.1.2  

补丁

    暂无

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
评论:0   参与:  0