KDE 1716 Published by Philipp Esselbach 0

KDE 3.4 Beta 2 has been released

February 9, 2005 (The Internet) - The KDE Project is pleased to announce the immediate availability of KDE 3.4 Beta 2, dubbed "Keinstein".

KDE 1716 Published by Philipp Esselbach 0

KDE 1716 Published by Philipp Esselbach 0

KDE Security Advisory: KOffice PDF Import Filter Vulnerability
Original Release Date: 2005-01-20
URL: http://www.kde.org/info/security/advisory-20050120-1.txt

0. References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0064
http://www.idefense.com/application/poi/display?id=186&type=vulnerabilities


1. Systems affected:

KOffice 1.3 up to including KOffice 1.3.5

2. Overview:

The KOffice PDF Import Filter shares code with xpdf. xpdf contains a buffer overflow that can be triggered by a specially crafted PDF file.

KDE 1716 Published by Philipp Esselbach 0

The third release in the 1.3 series of the KDE Disk archiver (KDar) has been released

KDE 1716 Published by Philipp Esselbach 0

KDE Security Advisory: ftp kioslave command injection
Original Release Date: 2005-01-01

URL: http://www.kde.org/info/security/advisory-20050101-1.txt

0. References

http://www.securityfocus.com/bid/11827 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1165

1. Systems affected:

All KDE releases up to including KDE 3.3.2.

2. Overview:

KDE applications which use the ftp kioslave, e.g. Konqueror, allow remote attackers to execute arbitrary FTP commands via an ftp://URL that contains an URL-encoded newline ( %0a ) before the ftp command, which causes the commands to be inserted into the resulting FTP session.

Due to similiarities between the ftp and the SMTP protocol, this vulnerability allows to misuse the ftp slave to connect to a SMTP server and issue arbitrary commands, like sending an email.