Vulnerability Note VU#820798

KDE Personal Information Management suite "kdepim" contains a buffer overflow vulnerability in VCF information reader

Original Release date: 27 Jan 2004 | Last revised: 27 Jan 2004

Overview

KDE Personal Information Management suite "kdepim" contains a buffer overflow vulnerability. Exploitation of this vulnerability could lead to the arbitrary execution of commands.

Description

KDE Personal Information Management suite shipped with KDE versions 3.1.0 through 3.1.4 contains a buffer overflow vulnerability in the processing of VCF files.

If an attacker can trick a victim into opening a specially crafted .VCF file, the attacker may be able to gain information about a victim's data or execute arbitrary commands
with the victim's privileges. This vulnerability may also be remotely exploited if the victim has previews for remote files enabled, however this feature is disabled by default.

Impact

An attacker may be able to gain information about a victim's data or execute arbitrary commands with the victim's privileges.

Solution

Upgrade to KDE version 3.1.5 or apply the patch to version 3.1.4.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
ConectivaAffected-27 Jan 2004
KDE Desktop Environment ProjectAffected-27 Jan 2004
MandrakeSoftAffected-27 Jan 2004
Red Hat Inc.Affected-27 Jan 2004
SlackwareAffected-27 Jan 2004
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

This vulnerability was discovered by Dirk Mueller of KDE and reported in their advisory.

This document was written by Stacey Stewart.

Other Information

  • CVE IDs: CAN-2003-0988
  • Date Public: 14 Jan 2004
  • Date First Published: 27 Jan 2004
  • Date Last Updated: 27 Jan 2004
  • Severity Metric: 8.10
  • Document Revision: 11

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.