KDE KPF Icon Option File Disclosure Vulnerability
BID:5951
Info
KDE KPF Icon Option File Disclosure Vulnerability
| Bugtraq ID: | 5951 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1224 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Vulnerability announced by KDE. |
| Vulnerable: |
KDE KDE 3.0.3 a KDE KDE 3.0.3 KDE KDE 3.0.2 KDE KDE 3.0.1 |
| Not Vulnerable: |
KDE KDE 3.0.4 |
Discussion
KDE KPF Icon Option File Disclosure Vulnerability
A vulnerability has been discovered in the kpf file sharing utility. KDE is available for the Linux operating system.
It has been reported that by passing a malicious file request to kpf, it is possible for a remote attacker to access files outside of the 'shared directory' root. The ability to read files outside of the shared root directory would be dependent upon the privileges of the kpf process.
A vulnerability has been discovered in the kpf file sharing utility. KDE is available for the Linux operating system.
It has been reported that by passing a malicious file request to kpf, it is possible for a remote attacker to access files outside of the 'shared directory' root. The ability to read files outside of the shared root directory would be dependent upon the privileges of the kpf process.
Exploit / POC
KDE KPF Icon Option File Disclosure Vulnerability
This vulnerability may be exploited with a web browser.
The following proof of concept was supplied by Ajay R Ramjatan <[email protected]>:
http://127.0.0.1:8001/?icon=/usr/local/kde/share/icons/hicolor/32x32/mimetypes/image.png
This vulnerability may be exploited with a web browser.
The following proof of concept was supplied by Ajay R Ramjatan <[email protected]>:
http://127.0.0.1:8001/?icon=/usr/local/kde/share/icons/hicolor/32x32/mimetypes/image.png
Solution / Fix
KDE KPF Icon Option File Disclosure Vulnerability
Solution:
RedHat has released an advisory, RHSA-2002:220-40, that contains many fixes. Information about obtaining and applying fixes are available in the referenced advisory.
A patch is available and the issue has been addressed in the latest KDE release:
KDE KDE 3.0.1
KDE KDE 3.0.2
KDE KDE 3.0.3
KDE KDE 3.0.3 a
Solution:
RedHat has released an advisory, RHSA-2002:220-40, that contains many fixes. Information about obtaining and applying fixes are available in the referenced advisory.
A patch is available and the issue has been addressed in the latest KDE release:
KDE KDE 3.0.1
-
KDE KDE 3.0.4
http://download.kde.org/stable/3.0.4
KDE KDE 3.0.2
-
KDE KDE 3.0.4
http://download.kde.org/stable/3.0.4
KDE KDE 3.0.3
-
KDE KDE 3.0.4
http://download.kde.org/stable/3.0.4 -
KDE post-3.0.3-kdenetwork-kpf.diff
ftp://ftp.kde.org/pub/kde/security_patches
KDE KDE 3.0.3 a
-
KDE KDE 3.0.4
http://download.kde.org/stable/3.0.4 -
KDE post-3.0.3-kdenetwork-kpf.diff
ftp://ftp.kde.org/pub/kde/security_patches
References
KDE KPF Icon Option File Disclosure Vulnerability
References:
References: