USN-115-1: Kommander vulnerability
4 May 2005
Kommander vulnerability
Releases
Details
Eckhart Wörner discovered that Kommander opens files from remote and
possibly untrusted locations without user confirmation. Since
Kommander files can contain scripts, this would allow an attacker to
execute arbitrary code with the privileges of the user opening the
file.
The updated Kommander will not automatically open files from remote
locations, and files which do not end with ".kmdr" any more.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 5.04
-
kommander
-
In general, a standard system update will make all the necessary changes.