Submitted by KeesCook on Tue, 2005-05-03 12:01
Referenced CVEs:
CAN-2005-0754
Description:
===========================================================
Ubuntu Security Notice USN-115-1 May 03, 2005
kdewebdev vulnerability
CAN-2005-0754
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.04 (Hoary Hedgehog)
The following packages are affected:
kommander
The problem can be corrected by upgrading the affected package to
version 4:3.4.0-0ubuntu2.2. In general, a standard system upgrade is
sufficient to effect the necessary changes.
Details follow:
Eckhart Wörner discovered that Kommander opens files from remote and
possibly untrusted locations without user confirmation. Since
Kommander files can contain scripts, this would allow an attacker to
execute arbitrary code with the privileges of the user opening the
file.
The updated Kommander will not automatically open files from remote
locations, and files which do not end with ".kmdr" any more.


