KDE Security Advisory: ftp kioslave command injection
Original Release Date: 2005-01-01
URL:
http://www.kde.org/info/security/advisory-20050101-1.txt0. References
http://www.securityfocus.com/bid/11827 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-11651. Systems affected:
All KDE releases up to including KDE 3.3.2.
2. Overview:
KDE applications which use the ftp kioslave, e.g. Konqueror, allow remote attackers to execute arbitrary FTP commands via an ftp://URL that contains an URL-encoded newline ( %0a ) before the ftp command, which causes the commands to be inserted into the resulting FTP session.
Due to similiarities between the ftp and the SMTP protocol, this vulnerability allows to misuse the ftp slave to connect to a SMTP server and issue arbitrary commands, like sending an email.
KPlayer 0.5.3 has been released
amaroK 1.2-beta3 has been released
Knotebook, a KDE applet for notebooks, has been released
KDE Security Advisory: ftp kioslave command injection
Original Release Date: 2005-01-01
URL:
http://www.kde.org/info/security/advisory-20050101-1.txt0. References
http://www.securityfocus.com/bid/11827 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-11651. Systems affected:
All KDE releases up to including KDE 3.3.2.
DigikamImagePlugins 0.7.1 is out
KDE Security Advisory: kpdf integer overflows
Original Release Date: 2004-10-21
URL: http://www.kde.org/info/security/advisory-20041021-1.txt
Chris Evans notified the KDE security team about multiple integer overflow and integer arithmetic flaws in xpdf 3.0. These flaws, if exploited, can cause xpdf (and therefore kpdf) to hang using 100% CPU, crash the viewer or corrupt the program heaproblem:
Chris Evans notified the KDE security team about multiple integer overflow and integer arithmetic flaws in xpdf 3.0. These flaws, if exploited, can cause xpdf (and therefore kpdf) to hang using 100% CPU, crash the viewer or corrupt the program heap.
Digikam 0.7.1 beta1 has been released
Rekall version 2.2.3 (the latest stable release) and version 2.3.2 (development) are now available
ROSEGARDEN 1.0pre1 has been released
KTTS 0.2.0 has been released
KolourPaint 1.2.2 has been released
KDE 3.3.2 has been released
The second release in the 1.3 series of the KDE Disk archiver (KDar) is now available
Vversion 1.2-beta1 of the amaroK audio player has been released
Kst 1.0.0 has been reeleased
KOffice 1.3.5 has been released
A new test version of knoda is available
digikam 0.7 has been released
digiKam-0.7-rc1 has been released