KDE Postscript/PDF文件处理任意命令执行漏洞

漏洞信息详情

KDE Postscript/PDF文件处理任意命令执行漏洞

漏洞简介

KDE使用Ghostscript软件处理PS和PDF文件。
KDE在处理畸形PDF和PS文件时存在漏洞,远程攻击者可以利用这个漏洞可能以用户进程权限执行任意命令。
攻击者可以准备恶意PostScript或PDF文件,构建恶意WEB页诱使用户点击或EMAIL发送给用户打开,可导致嵌入的命令以用户进程权限执行。目前没有提供详细漏洞细节。

漏洞公告

厂商补丁:
Debian
——

http://www.debian.org/security/2003/dsa-284

KDE

目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

KDE KDE 2.2.2:

KDE Patch post-2.2.2-kdebase-thumbnail.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdebase-thumbnail.diff

KDE Patch post-2.2.2-kdegraphics-kdvi.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdegraphics-kdvi.diff

KDE Patch post-2.2.2-kdegraphics-kghostview-2.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdegraphics-kghostview-2.diff

KDE Patch post-2.2.2-kdelibs-kimgio.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdelibs-kimgio.diff

KDE KDE 3.0:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/” target=”_blank”>
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.1:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/” target=”_blank”>
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.2:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/” target=”_blank”>
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.3 a:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/” target=”_blank”>
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.3:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/” target=”_blank”>
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.4:

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/” target=”_blank”>
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.5 a:

KDE Patch post-3.0.5a-kdebase-thumbnail.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdebase-thumbnail.diff

KDE Patch post-3.0.5a-kdegraphics-kdvi.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdegraphics-kdvi.diff

KDE Patch post-3.0.5a-kdegraphics-kghostview.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdegraphics-kghostview.diff

KDE Patch post-3.0.5a-kdelibs-kimgio.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdelibs-kimgio.diff

KDE Upgrade KDE 3.0.5b

http://download.kde.org/stable/3.0.5b/” target=”_blank”>
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.1:

KDE Upgrade KDE 3.1.1a

http://download.kde.org/stable/3.1.1a/” target=”_blank”>
http://download.kde.org/stable/3.1.1a/

KDE KDE 3.1.1:

KDE Patch post-3.1.1-kdebase-thumbnail.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdebase-thumbnail.diff

KDE Patch post-3.1.1-kdegraphics-kdvi.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdegraphics-kdvi.diff

KDE Patch post-3.1.1-kdegraphics-kghostview.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdegraphics-kghostview.diff

KDE Patch post-3.1.1-kdelibs-kimgio.diff

ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdelibs-kimgio.diff

KDE Upgrade KDE 3.1.1a

http://download.kde.org/stable/3.1.1a/” target=”_blank”>
http://download.kde.org/stable/3.1.1a/
MandrakeSoft
————
MandrakeSoft已经为此发布了一个安全公告(MDKSA-2003:049)以及相应补丁:

MDKSA-2003:049:Updated kde3 packages fix arbitrary command execution

链接:http://www.linux-mandrake.com/en/security/2003/2003-049.php” target=”_blank”>
http://www.linux-mandrake.com/en/security/2003/2003-049.php

补丁下载:

Updated Packages:

Corporate Server 2.1:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdebase-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdebase-devel-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdebase-nsplugins-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdelibs-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdelibs-devel-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdegraphics-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdegraphics-devel-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/kdebase-3.0.5a-1.2mdk.src.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/kdelibs-3.0.5a-1.2mdk.src.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/kdegraphics-3.0.5a-1.2mdk.src.rpm

Mandrake Linux 9.0:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdebase-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdebase-devel-3.0.5a-1.2mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdebase-nsplugins-3.0.5a-1.2mdk.i586.rpm


参考网址

来源: www.kde.org
链接:http://www.kde.org/info/security/advisory-20030409-1.txt

来源: DEBIAN
名称: DSA-284
链接:http://www.debian.org/security/2003/dsa-284

来源: REDHAT
名称: RHSA-2003:002
链接:http://www.redhat.com/support/errata/RHSA-2003-002.html

来源: DEBIAN
名称: DSA-296
链接:http://www.debian.org/security/2003/dsa-296

来源: DEBIAN
名称: DSA-293
链接:http://www.debian.org/security/2003/dsa-293

来源: bugs.kde.org
链接:http://bugs.kde.org/show_bug.cgi?id=56808

来源: bugs.kde.org
链接:http://bugs.kde.org/show_bug.cgi?id=53343

来源: MANDRAKE
名称: MDKSA-2003:049
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2003:049

来源: BUGTRAQ
名称: 20030414 GLSA: kde-2.x (200304-05.1)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105034222521369&w=2

来源: BUGTRAQ
名称: 20030412 [Sorcerer-spells] KDE-SORCERER2003-04-12
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105017403010459&w=2

来源: BUGTRAQ
名称: 20030411 GLSA: kde-2.x (200304-05)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105012994719099&w=2

来源: BUGTRAQ
名称: 20030410 GLSA: kde-3.x (200304-04)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105001557020141&w=2

来源: CONECTIVA
名称: CLA-2003:747
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000747

来源: CONECTIVA
名称: CLA-2003:668
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000668

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享