KDE kvt格式化字符串漏洞

漏洞信息详情

KDE kvt格式化字符串漏洞

漏洞简介

KDE 1.1.2版本的kvt存在格式化字符串漏洞。本地用户借助包含格式化字符的DISPLAY环境变量执行任意命令。

漏洞公告

Carlos Eduardo Gorges has supplied a patch he wrote that will fix the problem in his post to Bugtraq. Since kvt is no longer supported and will be obsoleted when KDE 2.0 is released, it is suggested that users use this patch.
KDE kvt 1.1.2
@techlinux.com.br>

参考网址

来源: BID
名称: 1700
链接:http://www.securityfocus.com/bid/1700

来源: BUGTRAQ
名称: 20000919 kvt format bug
链接:http://www.securityfocus.com/archive/1/83914

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享