<title>Kommander: Insecure remote script execution</title>
Kommander executes remote scripts without confirmation, potentially
resulting in the execution of arbitrary code.
<announced>April 22, 2005</announced>
<revised>May 20, 2005: 02</revised>
3.3.2-r2
3.3.2-r2
KDE is a feature-rich graphical desktop environment for Linux and
Unix-like Operating Systems. Kommander is a visual dialog editor and
interpreter for KDE applications, part of the kdewebdev package.
Kommander executes data files from possibly untrusted locations without
user confirmation.
An attacker could exploit this to execute arbitrary code with the
permissions of the user running Kommander.
There is no known workaround at this time.
All kdewebdev users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=kde-base/kdewebdev-3.3.2-r2&quot;</code>
<uri link="">CAN-2005-0754</uri>
<uri link="">KDE Security Advisory: Kommander untrusted code execution</uri>
