SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#820798

KDE Personal Information Management suite "kdepim" contains a buffer overflow vulnerability in VCF information reader

Overview

KDE Personal Information Management suite "kdepim" contains a buffer overflow vulnerability. Exploitation of this vulnerability could lead to the arbitrary execution of commands.

I. Description

KDE Personal Information Management suite shipped with KDE versions 3.1.0 through 3.1.4 contains a buffer overflow vulnerability in the processing of VCF files.

If an attacker can trick a victim into opening a specially crafted .VCF file, the attacker may be able to gain information about a victim's data or execute arbitrary commands
with the victim's privileges. This vulnerability may also be remotely exploited if the victim has previews for remote files enabled, however this feature is disabled by default.

II. Impact

An attacker may be able to gain information about a victim's data or execute arbitrary commands with the victim's privileges.

III. Solution

Upgrade to KDE version 3.1.5 or apply the patch to version 3.1.4.

Systems Affected

VendorStatusDate NotifiedDate Updated
ConectivaVulnerable27-Jan-2004
KDE Desktop Environment ProjectVulnerable27-Jan-2004
MandrakeSoftVulnerable27-Jan-2004
Red Hat Inc.Vulnerable27-Jan-2004
SlackwareVulnerable27-Jan-2004

References


http://www.kde.org/info/security/advisory-20040114-1.txt
https://rhn.redhat.com/errata/RHSA-2004-006.html
http://www.secunia.com/advisories/10625/

Credit

This vulnerability was discovered by Dirk Mueller of KDE and reported in their advisory.

This document was written by Stacey Stewart.

Other Information

Date Public:2004-01-14
Date First Published:2004-01-27
Date Last Updated:2004-01-27
CERT Advisory: 
CVE-ID(s):CAN-2003-0988
NVD-ID(s):CAN-2003-0988
US-CERT Technical Alerts: 
Metric:8.10
Document Revision:11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader