Gentoo Linux Advisory: kde-2.x | Linux Today

Gentoo Linux Advisory: kde-2.x

Written By
Web Webster
Web Webster
Apr 13, 2003
- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200304-05
- - ---------------------------------------------------------------------

          PACKAGE : kde-2.x
          SUMMARY : aribitrary code execution
             DATE : 2003-04-11 08:43 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : =kdebase-2.2.2-r5, >=kdelibs-2.2.2a-r1
                    >=kdegraphics-2.2.2-r2
              CVE : 

- - ---------------------------------------------------------------------

- From advisory:

"KDE uses Ghostscript software for processing of PostScript (PS)
and PDF files in a way that allows for the execution of arbitrary
commands that can be contained in such files.

An attacker can prepare a malicious PostScript or PDF file which will
provide the attacker with access to the victim's account and privileges
when the victim opens this malicious file for viewing or when the
victim browses a directory containing such malicious file and has
file previews enabled.

An attacker can provide malicious files remotely to a victim in an
e-mail, as part of a webpage, via an ftp server and possible other 
means."

Read the full advisory at:
http://www.kde.org/info/security/advisory-20030409-1.txt

SOLUTION

It is recommended that all Gentoo Linux users who are running
kde-base/kde upgrade to fixed packages as follows:

emerge sync
emerge =kde-base/kdebase-2.2.2-r5
emerge =kde-base/kdelibs-2.2.2a-r1
emerge =kde-base/kdegraphics-2.2.2-r2
emerge clean

- - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz
kde@gentoo.org
- - ---------------------------------------------------------------------

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.