CVE
- Id
- 5777
- CVE No.
- CVE-2002-1393
- Status
- Candidate
- Description
- Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.
- Phase
- Modified (20080207)
- Votes
- ACCEPT(2) Cole, Green | MODIFY(1) Cox | NOOP(1) Christey
- Comments
- Cox> Addref: RHSA-2003:003 | Christey> REDHAT:RHSA-2003:002 | URL:http://www.redhat.com/support/errata/RHSA-2003-002.html
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 32378 | 5777 | CVE-2002-1393 | BUGTRAQ:20021221 KDE Security Advisory: Multiple vulnerabilities in KDE | View |
| 32379 | 5777 | CVE-2002-1393 | URL:http://marc.info/?l=bugtraq&m=104049734911544&w=2 | View |
| 32380 | 5777 | CVE-2002-1393 | CONFIRM:http://www.kde.org/info/security/advisory-20021220-1.txt | View |
| 32381 | 5777 | CVE-2002-1393 | CONECTIVA:CLA-2003:569 | View |
| 32382 | 5777 | CVE-2002-1393 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000569 | View |
| 32383 | 5777 | CVE-2002-1393 | DEBIAN:DSA-234 | View |
| 32384 | 5777 | CVE-2002-1393 | URL:http://www.debian.org/security/2003/dsa-234 | View |
| 32385 | 5777 | CVE-2002-1393 | DEBIAN:DSA-235 | View |
| 32386 | 5777 | CVE-2002-1393 | URL:http://www.debian.org/security/2003/dsa-235 | View |
| 32387 | 5777 | CVE-2002-1393 | DEBIAN:DSA-236 | View |
| 32388 | 5777 | CVE-2002-1393 | URL:http://www.debian.org/security/2003/dsa-236 | View |
| 32389 | 5777 | CVE-2002-1393 | DEBIAN:DSA-237 | View |
| 32390 | 5777 | CVE-2002-1393 | URL:http://www.debian.org/security/2003/dsa-237 | View |
| 32391 | 5777 | CVE-2002-1393 | DEBIAN:DSA-238 | View |
| 32392 | 5777 | CVE-2002-1393 | URL:http://www.debian.org/security/2003/dsa-238 | View |
| 32393 | 5777 | CVE-2002-1393 | DEBIAN:DSA-239 | View |
| 32394 | 5777 | CVE-2002-1393 | URL:http://www.debian.org/security/2003/dsa-239 | View |
| 32395 | 5777 | CVE-2002-1393 | DEBIAN:DSA-240 | View |
| 32396 | 5777 | CVE-2002-1393 | URL:http://www.debian.org/security/2003/dsa-240 | View |
| 32397 | 5777 | CVE-2002-1393 | DEBIAN:DSA-241 | View |
| 32398 | 5777 | CVE-2002-1393 | URL:http://www.debian.org/security/2003/dsa-241 | View |
| 32399 | 5777 | CVE-2002-1393 | DEBIAN:DSA-242 | View |
| 32400 | 5777 | CVE-2002-1393 | URL:http://www.debian.org/security/2003/dsa-242 | View |
| 32401 | 5777 | CVE-2002-1393 | DEBIAN:DSA-243 | View |
| 32402 | 5777 | CVE-2002-1393 | URL:http://www.debian.org/security/2003/dsa-243 | View |
| 32403 | 5777 | CVE-2002-1393 | MANDRAKE:MDKSA-2003:004 | View |
| 32404 | 5777 | CVE-2002-1393 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2003:004 | View |
| 32405 | 5777 | CVE-2002-1393 | BUGTRAQ:20021222 GLSA: kde-3.0.x | View |
| 32406 | 5777 | CVE-2002-1393 | URL:http://marc.info/?l=bugtraq&m=104066520330397&w=2 | View |
| 32407 | 5777 | CVE-2002-1393 | REDHAT:RHSA-2003:002 | View |
| 32408 | 5777 | CVE-2002-1393 | URL:http://www.redhat.com/support/errata/RHSA-2003-002.html | View |
| 32409 | 5777 | CVE-2002-1393 | REDHAT:RHSA-2003:003 | View |
| 32410 | 5777 | CVE-2002-1393 | URL:http://www.redhat.com/support/errata/RHSA-2003-003.html | View |
| 32411 | 5777 | CVE-2002-1393 | BID:6462 | View |
| 32412 | 5777 | CVE-2002-1393 | URL:http://www.securityfocus.com/bid/6462 | View |
| 32413 | 5777 | CVE-2002-1393 | SECUNIA:8103 | View |
| 32414 | 5777 | CVE-2002-1393 | URL:http://secunia.com/advisories/8103 | View |
| 32415 | 5777 | CVE-2002-1393 | SECUNIA:8067 | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 64010 | JVNDB-2002-000337 | Red Hat Linux の KDE における任意のコマンドが実行される脆弱性 | KDE には、ユーザからシェルに渡される引数に対するチェックが不適切であるため、ユーザに任意のコマンドを含む URL やメールアドレス、ファイル名をユーザに利用させることにより、任意のコマンドが実行される脆弱性が存在します。 | CVE-2002-1393 | 5777 | 7.5 | http://jvndb.jvn.jp/ja/contents/2002/JVNDB-2002-000337.html | View |