Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
Link | Tags |
---|---|
http://www.kde.org/info/security/advisory-20050420-1.txt | patch vendor advisory |
http://marc.info/?l=bugtraq&m=111419664411051&w=2 | mailing list |
http://secunia.com/advisories/15060 | third party advisory patch vendor advisory |
http://www.securityfocus.com/bid/13313 | vdb entry patch vendor advisory |
ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.0-kdewebdev-kommander.diff | vendor advisory |