KDbg Arbitrary Command Execution Vulnerability
BID:13845
Info
KDbg Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 13845 |
| Class: | Design Error |
| CVE: |
CVE-2003-0644 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 07 2003 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Matt Zimmerman is credited with the discovery of this vulnerability. |
| Vulnerable: |
Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 KDbg KDbg 1.2.8 KDbg KDbg 1.2.7 KDbg KDbg 1.2.6 KDbg KDbg 1.2.5 KDbg KDbg 1.2.4 KDbg KDbg 1.2.3 KDbg KDbg 1.2.2 KDbg KDbg 1.2.1 KDbg KDbg 1.2 KDbg KDbg 1.1 |
| Not Vulnerable: |
KDbg KDbg 1.2.9 |
Discussion
KDbg Arbitrary Command Execution Vulnerability
KDbg is prone to a vulnerability that could permit the execution of arbitrary commands.
An attacker can exploit this vulnerability to inject malicious commands to be run under the permissions of the current KDbg session.
This issue affects KDbg versions 1.1.0 to 1.2.8 inclusive. This issue was originally reported to be addressed in version 1.2.8, it was later proven that is not the case.
The vendor has released an update in KDbg version 1.2.9.
KDbg is prone to a vulnerability that could permit the execution of arbitrary commands.
An attacker can exploit this vulnerability to inject malicious commands to be run under the permissions of the current KDbg session.
This issue affects KDbg versions 1.1.0 to 1.2.8 inclusive. This issue was originally reported to be addressed in version 1.2.8, it was later proven that is not the case.
The vendor has released an update in KDbg version 1.2.9.
Exploit / POC
KDbg Arbitrary Command Execution Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
KDbg Arbitrary Command Execution Vulnerability
Solution:
The vendor has addressed this issue in KDbg version 1.2.9 and later.
RedHat Linux has released advisory RHSA-2005:416-04 addressing this issue for RedHat Enterprise Linux and Advanced Workstation for the Itanium Processor. Please see the referenced advisory for further information.
KDbg KDbg 1.1
KDbg KDbg 1.2
KDbg KDbg 1.2.1
KDbg KDbg 1.2.2
KDbg KDbg 1.2.3
KDbg KDbg 1.2.4
KDbg KDbg 1.2.5
KDbg KDbg 1.2.6
KDbg KDbg 1.2.7
KDbg KDbg 1.2.8
Solution:
The vendor has addressed this issue in KDbg version 1.2.9 and later.
RedHat Linux has released advisory RHSA-2005:416-04 addressing this issue for RedHat Enterprise Linux and Advanced Workstation for the Itanium Processor. Please see the referenced advisory for further information.
KDbg KDbg 1.1
-
KDbg kdbg-1.2.10.tar.gz
http://prdownloads.sourceforge.net/kdbg/kdbg-1.2.10.tar.gz?download
KDbg KDbg 1.2
-
KDbg kdbg-1.2.10.tar.gz
http://prdownloads.sourceforge.net/kdbg/kdbg-1.2.10.tar.gz?download
KDbg KDbg 1.2.1
-
KDbg kdbg-1.2.10.tar.gz
http://prdownloads.sourceforge.net/kdbg/kdbg-1.2.10.tar.gz?download
KDbg KDbg 1.2.2
-
KDbg kdbg-1.2.10.tar.gz
http://prdownloads.sourceforge.net/kdbg/kdbg-1.2.10.tar.gz?download
KDbg KDbg 1.2.3
-
KDbg kdbg-1.2.10.tar.gz
http://prdownloads.sourceforge.net/kdbg/kdbg-1.2.10.tar.gz?download
KDbg KDbg 1.2.4
-
KDbg kdbg-1.2.10.tar.gz
http://prdownloads.sourceforge.net/kdbg/kdbg-1.2.10.tar.gz?download
KDbg KDbg 1.2.5
-
KDbg kdbg-1.2.10.tar.gz
http://prdownloads.sourceforge.net/kdbg/kdbg-1.2.10.tar.gz?download
KDbg KDbg 1.2.6
-
KDbg kdbg-1.2.10.tar.gz
http://prdownloads.sourceforge.net/kdbg/kdbg-1.2.10.tar.gz?download
KDbg KDbg 1.2.7
-
KDbg kdbg-1.2.10.tar.gz
http://prdownloads.sourceforge.net/kdbg/kdbg-1.2.10.tar.gz?download
KDbg KDbg 1.2.8
-
KDbg kdbg-1.2.10.tar.gz
http://prdownloads.sourceforge.net/kdbg/kdbg-1.2.10.tar.gz?download
References
KDbg Arbitrary Command Execution Vulnerability
References:
References: