J-Security Center

Title: KDE Personal Information Management Suite VCF File Remote Buffer Overflow Vulnerability

Severity: HIGH

Description:

KDE Personal Information Management Suite (kdepim) helps users organize mail, tasks, appointments, contacts etc. It is packaged with KDE, a graphical desktop for the X Window System.

A buffer overflow vulnerability has been reported to exist in the KDE Personal Information Management Suite (kdepim) that may allow a remote attacker to execute arbitrary code on a vulnerable system. The issue presents itself when an attacker sends a malformed VCF file to a user on a vulnerable system. Due to a problem with the file information reader of VCF files, an attacker may be able to execute arbitrary code on a vulnerable system if the malicious VCF file is opened by the user.

The condition exists due to insufficient boundary checking. Because of this, it may be possible for a remote attacker to gain unauthorized access to a system running the vulnerable software.

Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code in the context of the user.

Affected Products:

  • Conectiva Linux 9.0.0
  • KDE KDE 3.1.0
  • KDE KDE 3.1.1
  • KDE KDE 3.1.1 a
  • KDE KDE 3.1.2
  • KDE KDE 3.1.3
  • KDE KDE 3.1.4
  • MandrakeSoft Linux Mandrake 9.1.0
  • MandrakeSoft Linux Mandrake 9.1.0 ppc
  • MandrakeSoft Linux Mandrake 9.2.0
  • MandrakeSoft Linux Mandrake 9.2.0 amd64
  • RedHat Desktop 3.0.0
  • RedHat Enterprise Linux AS 3
  • RedHat Enterprise Linux ES 3
  • RedHat Enterprise Linux WS 3
  • RedHat Fedora Core1
  • RedHat Linux 9.0.0 i386
  • RedHat kdepim-3.1-5.i386.rpm
  • RedHat kdepim-devel-3.1-5.i386.rpm
  • S.u.S.E. Linux 8.1.0
  • S.u.S.E. Linux Personal 8.2.0
  • Slackware Linux -current
  • Slackware Linux 9.0.0
  • Slackware Linux 9.1.0

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.