[Full-Disclosure] [ GLSA 200501-18 ] KDE FTP KIOslave: Command injection

From: Sune Kloppenborg Jeppesen (jaervosz_at_gentoo.org)
Date: 01/11/05

  • Next message: class 101: "Re: [Full-Disclosure] VERITAS Backup Exec 8.x/9.x Remote UniversalExploit"
    To: gentoo-announce@gentoo.org
    Date: Tue, 11 Jan 2005 14:33:11 +0100
    
    
    
    

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 200501-18
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                                http://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

      Severity: Normal
         Title: KDE FTP KIOslave: Command injection
          Date: January 11, 2005
          Bugs: #73759
            ID: 200501-18

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    The FTP KIOslave contains a bug allowing users to execute arbitrary FTP
    commands.

    Background
    ==========

    KDE is a feature-rich graphical desktop environment for Linux and
    Unix-like Operating Systems. KDE provided KIOslaves for many protocols
    in the kdelibs package, one of them being FTP. These are used by KDE
    applications such as Konqueror.

    Affected packages
    =================

        -------------------------------------------------------------------
         Package / Vulnerable / Unaffected
        -------------------------------------------------------------------
      1 kde-base/kdelibs < 3.3.2-r2 >= 3.3.2-r2
                                                              *>= 3.2.3-r5

    Description
    ===========

    The FTP KIOslave fails to properly parse URL-encoded newline
    characters.

    Impact
    ======

    An attacker could exploit this to execute arbitrary FTP commands on the
    server and due to similiarities between the FTP and the SMTP protocol,
    this vulnerability also allows an attacker to connect to a SMTP server
    and issue arbitrary commands, for example sending an email.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All kdelibs users should upgrade to the latest version:

        # emerge --sync
        # emerge --ask --oneshot --verbose kde-base/kdelibs

    Note: There is currently no fixed stable 3.3.x version for sparc.

    References
    ==========

      [ 1 ] KDE Security Advisory: ftp kioslave command injection
            http://www.kde.org/info/security/advisory-20050101-1.txt
      [ 2 ] CAN-2004-1165
            http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1165

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

      http://security.gentoo.org/glsa/glsa-200501-18.xml

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users machines is of utmost
    importance to us. Any security concerns should be addressed to
    security@gentoo.org or alternatively, you may file a bug at
    http://bugs.gentoo.org.

    License
    =======

    Copyright 2005 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    http://creativecommons.org/licenses/by-sa/2.0

    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: class 101: "Re: [Full-Disclosure] VERITAS Backup Exec 8.x/9.x Remote UniversalExploit"

    Relevant Pages

    • [Full-Disclosure] [gentoo-announce] [ GLSA 200501-18 ] KDE FTP KIOslave: Command injection
      ... The FTP KIOslave contains a bug allowing users to execute arbitrary FTP ... KDE provided KIOslaves for many protocols ... An attacker could exploit this to execute arbitrary FTP commands on the ...
      (Full-Disclosure)
    • [ GLSA 200501-18 ] KDE FTP KIOslave: Command injection
      ... The FTP KIOslave contains a bug allowing users to execute arbitrary FTP ... KDE provided KIOslaves for many protocols ... An attacker could exploit this to execute arbitrary FTP commands on the ...
      (Full-Disclosure)
    • [ GLSA 200501-18 ] KDE FTP KIOslave: Command injection
      ... The FTP KIOslave contains a bug allowing users to execute arbitrary FTP ... KDE provided KIOslaves for many protocols ... An attacker could exploit this to execute arbitrary FTP commands on the ...
      (Bugtraq)
    • Re: Mime type?
      ... options for not sending these commands. ... >>I was into the Fetch FTP web site and this is what I found - it looks ... >> My server does not recognize them. ...
      (microsoft.public.inetserver.iis)
    • Re: Missing bin directory
      ... and I'm wondering how I can get back some basic commands such as ... I have ftp access. ... or from another identical system. ... Let's take a look on my box what packages are in bin: ...
      (comp.os.linux.misc)

  • Quantcast