USN-115-1: Kommander vulnerability

Ubuntu Security Notice USN-115-1

3rd May, 2005

kdewebdev vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 5.04

Details

Eckhart W�r discovered that Kommander opens files from remote and
possibly untrusted locations without user confirmation. Since
Kommander files can contain scripts, this would allow an attacker to
execute arbitrary code with the privileges of the user opening the
file.

The updated Kommander will not automatically open files from remote
locations, and files which do not end with ".kmdr" any more.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 5.04:
kommander

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

None

References

CVE-2005-0754