Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.idefense.com/application/poi/display?id=104&type=vulnerabilities http://www.kde.org/info/security/advisory-20040517-1.txt http://freebsd.kde.org/index.php#n20040517
http://www.vuxml.org/freebsd/df333ede-a8ce-11d8-9c6d-0020ed76ef5a.html
Insight
The following packages are affected:
linux-opera
opera
kdelibs
CVE-2004-0411
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter '-' characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.
Severity
Classification
-
CVE CVE-2004-0411 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities