KDE Postscript/PDF File Processing Arbitrary Command Execution Vulnerability

BID:7318

Info

KDE Postscript/PDF File Processing Arbitrary Command Execution Vulnerability

Bugtraq ID: 7318
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2003-0204
Remote: Yes
Local: No
Published: Apr 10 2003 12:00AM
Updated: Jul 11 2009 09:06PM
Credit: This vulnerability was reported by the KDE team.
Vulnerable: KDE KDE 3.1.1
+ S.u.S.E. Linux Personal 8.2
+ S.u.S.E. Linux Personal 8.2
KDE KDE 3.1
+ Redhat Linux 9.0 i386
+ SuSE Linux 8.1
+ SuSE Linux 8.1
KDE KDE 3.0.5 b
KDE KDE 3.0.5 a
+ Redhat Linux 8.0 i386
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.3 i386
KDE KDE 3.0.5
KDE KDE 3.0.4
+ Gentoo Linux 1.4 _rc1
+ Gentoo Linux 1.2
+ Gentoo Linux 1.2
KDE KDE 3.0.3 a
KDE KDE 3.0.3
+ Conectiva Linux Enterprise Edition 1.0
+ FreeBSD FreeBSD 4.7 -STABLE
+ FreeBSD FreeBSD 4.7 -STABLE
+ Mandriva Linux Mandrake 9.0
+ Mandriva Linux Mandrake 9.0
KDE KDE 3.0.2
+ Mandriva Linux Mandrake 8.2
KDE KDE 3.0.1
KDE KDE 3.0
KDE KDE 2.2.2
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Debian Linux 3.0
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 IA-32
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.1
+ Redhat Advanced Workstation for the Itanium Processor 2.1
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1
+ Redhat Enterprise Linux WS 2.1
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 i386
+ Redhat Linux Advanced Work Station 2.1
+ Sun Linux 5.0.7
+ Sun Linux 5.0.7
+ Sun Linux 5.0.6
+ Sun Linux 5.0.6
+ Sun Linux 5.0.5
+ Sun Linux 5.0.5
KDE KDE 2.2.1
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ Caldera OpenLinux Workstation 3.1
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
KDE KDE 2.2
KDE KDE 2.1.2
KDE KDE 2.1.1
KDE KDE 2.1
KDE KDE 2.0.1
KDE KDE 2.0
Not Vulnerable: KDE KDE 3.1.1 a
KDE KDE 3.0.5 b

Discussion

KDE Postscript/PDF File Processing Arbitrary Command Execution Vulnerability

A problem with KDE could lead to arbitrary command execution.

The vulnerability exists when KDE attempts to process specially formatted PDF and PS (postscript) files. Exploitation of this vulnerability will result in the execution of shell commands on the vulnerable system.

Exploit / POC

KDE Postscript/PDF File Processing Arbitrary Command Execution Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

KDE Postscript/PDF File Processing Arbitrary Command Execution Vulnerability

Solution:
Red Hat has released a security advisory (RHSA-2003:002-01), which addresses the issue. Please see the attached advisory for details on obtaining fixes.

Red Hat has also released an advisory and fixes for Red Hat Enterprise Linux. Fixes for Enterprise Linux may be obtained through the Red Hat Network.

KDE 3.0.5b and 3.1.1a are not vulnerable to this issue.

Mandrake Linux has released an advisory (MDKSA-2003:049) and fixes. Information about obtaining and applying fixes are available in the referenced advisory.

Gentoo Linux has released an updated advisory (200304-05.1) for kde 2.x systems. Affected users are advised to upgrade systems by issuing the following commands:

emerge sync
emerge \=kde-base/kdebase-2.2.2-r5
emerge \=kde-base/kdelibs-2.2.2a-r2
emerge \=kde-base/kdegraphics-2.2.2-r2
emerge clean

Gentoo Linux has released an advisory. Users who have installed kde-base/kde are advised to upgrade to kde-3.1.1a or kde-3.0.5b by issuing the following commands:

emerge sync
emerge kde OR \=kde-base/kde-3.0.5b
emerge clean

Gentoo Linux has released a new advisory (200304-05) for kde 2.x systems. Affected users are advised to upgrade systems by issuing the following commands:

emerge sync
emerge \=kde-base/kdebase-2.2.2-r5
emerge \=kde-base/kdelibs-2.2.2a-r1
emerge \=kde-base/kdegraphics-2.2.2-r2
emerge clean

Debian has released an advisory DSA 284-1. Information about obtaining and applying fixes are available in the referenced advisory. Users of the apt-get system can upgrade their systems by issuing the following commands:

apt-get update
apt-get upgrade

Sorcerer Linux has released an advisory. Affected users are advised to issue the following commands to upgrade their systems:

augur synch && augur newer && augur update

Gentoo Linux has released a new advisory for kde 3.1.1a systems. It is recommended that all Gentoo Linux users who are running kde-base/kdegraphics upgrade to kdegraphics-3.1.1a-r1 as follows:

emerge sync
emerge kdegraphics
emerge clean

Slackware Linux has released an advisory. Users of KDE are advised to upgrade systems to KDE 3.1.1a by issuing the following commands as the root user:

upgradepkg *.tgz

Debian has released a security advisory (DSA 293-1) which contains fixes addressing this issue. Further information regarding how to obtain and apply fixes can be found in the attached advisory.

SuSE has released an advisory SuSE-SA:2003:026. SuSE has advised affected users to update systems using YaST2. Further information is available in the referenced advisory.

Debian has released a new security advisory (DSA 296-1). Information about obtaining and applying fixes can be found in the referenced advisory. Users of the apt-get system are advised to issue the following commands to update affected systems:

apt-get update
apt-get upgrade

Sun has released updates for Sun Linux 5.0.5.

Conectiva has released an advisory (CLA-2003:668) to address this issue. Please see the attached advisory for details on obtaining and applying fixes manually. Users can also upgrade using the following apt commands:

apt-get update
apt-get upgrade

Conectiva has released an advisory CLA-2003:747, including fixes to address this and other issues.

SUSE has released an advisory SuSE-SA:2004:009 with additional fixes to address this and other issues. Please see the advisory for more information.

Fixes available:


KDE KDE 2.2.2

KDE KDE 3.0

KDE KDE 3.0.1

KDE KDE 3.0.2

KDE KDE 3.0.3

KDE KDE 3.0.3 a

KDE KDE 3.0.4

KDE KDE 3.0.5 a

KDE KDE 3.0.5

KDE KDE 3.0.5 b

KDE KDE 3.1

KDE KDE 3.1.1

References

KDE Postscript/PDF File Processing Arbitrary Command Execution Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report