KDE Multiple URI Handler Vulnerabilities

BID:10358

Info

KDE Multiple URI Handler Vulnerabilities

Bugtraq ID: 10358
Class: Input Validation Error
CVE: CVE-2004-0411
Remote: Yes
Local: No
Published: May 17 2004 12:00AM
Updated: Jul 12 2009 04:07AM
Credit: The telnet URI handler vulnerability was identified by iDEFENSE. The other vulnerabilities were disclosed by KDE.
Vulnerable: Redhat Fedora Core1
KDE KDE 3.2.2
+ KDE KDE 3.2.2
+ Redhat Fedora Core2
KDE KDE 3.1.5
KDE KDE 3.1.4
KDE KDE 3.1.3
+ Redhat Desktop 3.0
+ Redhat Desktop 3.0
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux WS 3
KDE KDE 3.1.2
+ KDE KDE 3.1.2
KDE KDE 3.1.1 a
KDE KDE 3.1.1
+ S.u.S.E. Linux Personal 8.2
+ S.u.S.E. Linux Personal 8.2
KDE KDE 3.1
+ Redhat Linux 9.0 i386
+ SuSE Linux 8.1
+ SuSE Linux 8.1
KDE KDE 3.0.5 b
KDE KDE 3.0.5 a
+ Redhat Linux 8.0 i386
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.3 i386
KDE KDE 3.0.5
KDE KDE 3.0.4
+ Gentoo Linux 1.4 _rc1
+ Gentoo Linux 1.2
+ Gentoo Linux 1.2
KDE KDE 3.0.3 a
KDE KDE 3.0.3
+ Conectiva Linux Enterprise Edition 1.0
+ FreeBSD FreeBSD 4.7 -STABLE
+ FreeBSD FreeBSD 4.7 -STABLE
+ Mandriva Linux Mandrake 9.0
+ Mandriva Linux Mandrake 9.0
KDE KDE 3.0.2
+ Mandriva Linux Mandrake 8.2
KDE KDE 3.0.1
KDE KDE 3.0
KDE KDE 2.2.2
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Debian Linux 3.0
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 IA-32
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.1
+ Redhat Advanced Workstation for the Itanium Processor 2.1
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1
+ Redhat Enterprise Linux WS 2.1
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 i386
+ Redhat Linux Advanced Work Station 2.1
+ Sun Linux 5.0.7
+ Sun Linux 5.0.7
+ Sun Linux 5.0.6
+ Sun Linux 5.0.6
+ Sun Linux 5.0.5
+ Sun Linux 5.0.5
KDE KDE 2.2.1
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ Caldera OpenLinux Workstation 3.1
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
KDE KDE 2.2
KDE KDE 2.1.2
KDE KDE 2.1.1
KDE KDE 2.1
KDE KDE 2.0.1
KDE KDE 2.0 BETA
KDE KDE 2.0
KDE KDE 1.2
- SuSE Linux 6.4
KDE KDE 1.1.2
+ Caldera OpenLinux 2.3
+ Mandriva Linux Mandrake 7.0
KDE KDE 1.1.1
KDE KDE 1.1
Not Vulnerable:

Discussion

KDE Multiple URI Handler Vulnerabilities

It has been reported that KDE is prone to multiple input validation vulnerabilities in various URI handlers. The issues are reported to exist due to insufficient sanitization of user-supplied input by the telnet, rlogin, ssh and mailto URI handlers. Specifically, if a '-' character is present at the beginning of a host name, options may be passed to the programs to carry out an attack.

Exploit / POC

KDE Multiple URI Handler Vulnerabilities

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

KDE Multiple URI Handler Vulnerabilities

Solution:
KDE has released a security advisory to address these issues. Please see the referenced advisory for more information.

Conectiva has released a security advisory (CLA-2004:843) that addresses this issue. Please see the referenced advisory for information and fixes.

RedHat has released a security advisory (RHSA-2004:222-11) that addresses this issue. Please see the referenced advisory for updated information and fixes.

Slackware has released a security advisory (SSA:2004-238-01) that addresses this issue. Please see the referenced advisory for updated information and fixes.

Red Hat Fedore has released an advisory FEDORA-2004-121 that addresses this issue. Please see the referenced advisory for updated information and fixes.

RedHat has released advisory FEDORA-2004-122 to provide fixes for Fedora. Please see the attached advisory for details on obtaining and applying fixes.

Gentoo has released advisory GLSA 200405-11 to provide fixes for this issue. Please see the attached advisory for details on obtaining and applying fixes. Gentoo users may carry out the following commands to upgrade their computers:

Users of KDE 3.1 should upgrade to the corrected version of kdelibs:

# emerge sync
# emerge -pv "=kde-base/kdelibs-3.1.5-r1"
# emerge "=kde-base/kdelibs-3.1.5-r1"

Users of KDE 3.2 should upgrade to the latest available version of
kdelibs:

# emerge sync
# emerge -pv ">=kde-base/kdelibs-3.2.2-r1"
# emerge ">=kde-base/kdelibs-3.2.2-r1"

SuSE has released advisory SuSE-SA:2004:014 to provide fixes for this issue. Please see the attached advisory for details on obtaining and applying fixes.

Silicon Graphics has released advisory 20040509-01-U and fixes dealing with this and other issues for SGI ProPack 3. Please see the referenced advisory for more information.

Silicon Graphics has released advisory 20040508-01-U and fixes dealing with this and other issues for SGI ProPack 2.4. Please see the referenced advisory for more information.

Debian has released an advisory (DSA 518-1) with fixes to address this issue. Please see the referenced advisory for more information.


Redhat Fedora Core1

KDE KDE 2.2.2

KDE KDE 3.0

KDE KDE 3.0.5

KDE KDE 3.0.5 b

KDE KDE 3.1.1

KDE KDE 3.1.3

KDE KDE 3.1.4

KDE KDE 3.1.5

KDE KDE 3.2.2

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report