Jump to content

Security Advisory (MDKSA-2003:055): kopete


Recommended Posts

MandrakeSoft Security Advisory MDKSA-2003:055 : kopete

 

May 8th, 2003

Updated kopete packages fix vulnerability with GnuPG plugin

 

A vulnerability was discovered in versions of kopete, a KDE instant messenger client, prior to 0.6.2. This vulnerabiliy is in the GnuPG plugin that allows for users to send each other GPG-encrypted instant messages. The plugin passes encrypted messages to gpg, but does no checking to sanitize the commandline passed to gpg. This can allow remote users to execute arbitrary code, with the permissions of the user running kopete, on the local system.

 

 

The released versions of Mandrake GNU/Linux affected are:

  • 9.1

 

[*] 9.1/PPC

Full information about this advisory, including the updated packages, is available at:

www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:055

 

Other references:

http://cve.mitre.org/cgi-bin/cvename.cgi?n...e=CAN-2003-0256

http://kopete.kde.org/index.php?page=newss...s_version_0.6.2

 

Posted automatically by aru (mdksec2mub v0.0.5)

Link to comment
Share on other sites

 Share

×
×
  • Create New...