Kommander: Insecure remote script execution Kommander executes remote scripts without confirmation, potentially resulting in the execution of arbitrary code. Kommander 2005-04-22 2005-05-20 89092 remote 3.3.2-r2 3.3.2-r2

KDE is a feature-rich graphical desktop environment for Linux and Unix-like Operating Systems. Kommander is a visual dialog editor and interpreter for KDE applications, part of the kdewebdev package.

Kommander executes data files from possibly untrusted locations without user confirmation.

An attacker could exploit this to execute arbitrary code with the permissions of the user running Kommander.

There is no known workaround at this time.

All kdewebdev users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=kde-base/kdewebdev-3.3.2-r2"
CAN-2005-0754 KDE Security Advisory: Kommander untrusted code execution jaervosz jaervosz