CVE Vulnerabilities

CVE-2002-1393

Published: Jan 17, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.

Affected Software

NameVendorStart VersionEnd Version
KdeKde2.0 (including)2.0 (including)
KdeKde2.0.1 (including)2.0.1 (including)
KdeKde2.1 (including)2.1 (including)
KdeKde2.1.1 (including)2.1.1 (including)
KdeKde2.1.2 (including)2.1.2 (including)
KdeKde2.2 (including)2.2 (including)
KdeKde2.2.1 (including)2.2.1 (including)
KdeKde2.2.2 (including)2.2.2 (including)
KdeKde3.0 (including)3.0 (including)
KdeKde3.0.1 (including)3.0.1 (including)
KdeKde3.0.2 (including)3.0.2 (including)
KdeKde3.0.3 (including)3.0.3 (including)
KdeKde3.0.3a (including)3.0.3a (including)
KdeKde3.0.4 (including)3.0.4 (including)
KdeKde3.0.5 (including)3.0.5 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*
Red Hat Linux 9RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*

References