CVE-2002-1224: Medium severity KDE kde vulnerability
Published Oct 28, 2002
·Updated
Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.
Affected Software
4 affected components
KDE kde=3.0.1
KDE kde=3.0.2
KDE kde=3.0.3
KDE kde=3.0.3a
Remediation
Patch Available
Patch Available
Event History
Oct 28, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1224?
CVE-2002-1224 has a moderate severity rating due to its ability to allow unauthorized access to sensitive files.
2
How do I fix CVE-2002-1224?
To fix CVE-2002-1224, upgrade to a non-vulnerable version of KDE, specifically versions later than 3.0.3a.
3
What software is affected by CVE-2002-1224?
CVE-2002-1224 affects KDE versions 3.0.1, 3.0.2, 3.0.3, and 3.0.3a.
4
What type of vulnerability is CVE-2002-1224?
CVE-2002-1224 is a directory traversal vulnerability that allows remote attackers to read arbitrary files.
5
Can CVE-2002-1224 be exploited remotely?
Yes, CVE-2002-1224 can be exploited remotely through specifically crafted URL requests.