安全研究

安全漏洞
KDE Postscript/PDF文件处理任意命令执行漏洞

发布日期:2003-04-10
更新日期:2003-04-23

受影响系统:
KDE KDE 3.1.1
KDE KDE 3.1
KDE KDE 3.0.5a
KDE KDE 3.0.5
KDE KDE 3.0.4
KDE KDE 3.0.3
KDE KDE 3.0.1
KDE KDE 3.0
KDE KDE 2.2.1
KDE KDE 2.2
KDE KDE 2.1.2
KDE KDE 2.1.1
KDE KDE 2.1
KDE KDE 2.0.1
KDE KDE 2.0 BETA
KDE KDE 2.0
KDE KDE 2.2.2
    - Conectiva Linux 8.0
    - Debian Linux 3.0 arm
    - Debian Linux 3.0 powerpc
    - Debian Linux 3.0 68k
    - Debian Linux 3.0 i386
    - Debian Linux 3.0 sparc
    - Debian Linux 3.0 alpha
    - Debian Linux 3.0 IA-32
    - Mandrake Linux 8.2
    - Mandrake Linux 8.1
不受影响系统:
KDE KDE 3.1.1a
KDE KDE 3.0.5b
描述:
BUGTRAQ  ID: 7318
CVE(CAN) ID: CVE-2003-0204

KDE使用Ghostscript软件处理PS和PDF文件。

KDE在处理畸形PDF和PS文件时存在漏洞,远程攻击者可以利用这个漏洞可能以用户进程权限执行任意命令。

攻击者可以准备恶意PostScript或PDF文件,构建恶意WEB页诱使用户点击或EMAIL发送给用户打开,可导致嵌入的命令以用户进程权限执行。目前没有提供详细漏洞细节。

<*来源:KDE security advisory
  
  链接:http://www.kde.org/info/security/advisory-20030409-1.txt
        http://www.debian.org/security/2003/dsa-284
        http://www.linux-mandrake.com/en/security/2003/2003-049.php
*>

建议:
厂商补丁:

Debian
------
http://www.debian.org/security/2003/dsa-284

KDE
---
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

KDE KDE 2.2.2:

KDE Patch post-2.2.2-kdebase-thumbnail.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdebase-thumbnail.diff

KDE Patch post-2.2.2-kdegraphics-kdvi.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdegraphics-kdvi.diff

KDE Patch post-2.2.2-kdegraphics-kghostview-2.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdegraphics-kghostview-2.diff

KDE Patch post-2.2.2-kdelibs-kimgio.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-2.2.2-kdelibs-kimgio.diff

KDE KDE 3.0:

KDE Upgrade KDE 3.0.5b
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.1:

KDE Upgrade KDE 3.0.5b
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.2:

KDE Upgrade KDE 3.0.5b
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.3 a:

KDE Upgrade KDE 3.0.5b
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.3:

KDE Upgrade KDE 3.0.5b
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.4:

KDE Upgrade KDE 3.0.5b
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.0.5 a:

KDE Patch post-3.0.5a-kdebase-thumbnail.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdebase-thumbnail.diff

KDE Patch post-3.0.5a-kdegraphics-kdvi.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdegraphics-kdvi.diff

KDE Patch post-3.0.5a-kdegraphics-kghostview.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdegraphics-kghostview.diff

KDE Patch post-3.0.5a-kdelibs-kimgio.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.0.5a-kdelibs-kimgio.diff

KDE Upgrade KDE 3.0.5b
http://download.kde.org/stable/3.0.5b/

KDE KDE 3.1:

KDE Upgrade KDE 3.1.1a
http://download.kde.org/stable/3.1.1a/

KDE KDE 3.1.1:

KDE Patch post-3.1.1-kdebase-thumbnail.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdebase-thumbnail.diff

KDE Patch post-3.1.1-kdegraphics-kdvi.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdegraphics-kdvi.diff

KDE Patch post-3.1.1-kdegraphics-kghostview.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdegraphics-kghostview.diff

KDE Patch post-3.1.1-kdelibs-kimgio.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.1.1-kdelibs-kimgio.diff

KDE Upgrade KDE 3.1.1a
http://download.kde.org/stable/3.1.1a/

MandrakeSoft
------------
MandrakeSoft已经为此发布了一个安全公告(MDKSA-2003:049)以及相应补丁:
MDKSA-2003:049:Updated kde3 packages fix arbitrary command execution
链接:http://www.linux-mandrake.com/en/security/2003/2003-049.php

补丁下载:

Updated Packages:

Corporate Server 2.1:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdebase-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdebase-devel-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdebase-nsplugins-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdelibs-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdelibs-devel-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdegraphics-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kdegraphics-devel-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/kdebase-3.0.5a-1.2mdk.src.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/kdelibs-3.0.5a-1.2mdk.src.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/kdegraphics-3.0.5a-1.2mdk.src.rpm

Mandrake Linux 9.0:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdebase-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdebase-devel-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdebase-nsplugins-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdelibs-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdelibs-devel-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdegraphics-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/kdegraphics-devel-3.0.5a-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/SRPMS/kdebase-3.0.5a-1.2mdk.src.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/SRPMS/kdelibs-3.0.5a-1.2mdk.src.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/SRPMS/kdegraphics-3.0.5a-1.2mdk.src.rpm

Mandrake Linux 9.1:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kdebase-3.1-83.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kdebase-devel-3.1-83.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kdebase-kdm-3.1-83.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kdebase-nsplugins-3.1-83.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kdelibs-3.1-58.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kdelibs-common-3.1-58.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kdelibs-devel-3.1-58.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kdelibs-static-devel-3.1-58.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kdegraphics-3.1-9.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kdegraphics-devel-3.1-9.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/SRPMS/kdebase-3.1-83.1mdk.src.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/SRPMS/kdelibs-3.1-58.1mdk.src.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/SRPMS/kdegraphics-3.1-9.1mdk.src.rpm

Mandrake Linux 9.1/PPC:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/kdebase-3.1-83.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/kdebase-devel-3.1-83.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/kdebase-kdm-3.1-83.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/kdebase-nsplugins-3.1-83.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/kdelibs-3.1-58.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/kdelibs-common-3.1-58.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/kdelibs-devel-3.1-58.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/kdelibs-static-devel-3.1-58.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/kdegraphics-3.1-9.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/kdegraphics-devel-3.1-9.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/SRPMS/kdebase-3.1-83.1mdk.src.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/SRPMS/kdelibs-3.1-58.1mdk.src.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/SRPMS/kdegraphics-3.1-9.1mdk.src.rpm

上述升级软件还可以在下列地址中的任意一个镜像ftp服务器上下载:
http://www.mandrakesecure.net/en/ftp.php

浏览次数:3236
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障