CVE-2003-0204: High severity KDE kde vulnerability
KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure kghostview so that it launches Ghostscript with the -dPARANOIDSAFER and -dSAFER arguments when rendering PostScript (PS) or PDF files to enable safer mode and prevent execution of arbitrary commands.
kghostview (Ghostscript invocation) Ghostscript arguments / safety flags = -dPARANOIDSAFER -dSAFER
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0204?
CVE-2003-0204 is considered a moderate severity vulnerability due to its capability to execute arbitrary commands.
How do I fix CVE-2003-0204?
To fix CVE-2003-0204, upgrade to a version of KDE that includes the necessary -dPARANOIDSAFER and -dSAFER arguments in the Ghostscript viewer settings.
What systems are affected by CVE-2003-0204?
CVE-2003-0204 affects KDE versions from 2.0 to 3.1.1, including multiple specific sub-versions.
What types of files can exploit CVE-2003-0204?
CVE-2003-0204 can be exploited via specially crafted PostScript (PS) or PDF files.
Can CVE-2003-0204 be exploited remotely?
Yes, CVE-2003-0204 could be exploited remotely if a user opens a malicious PS or PDF file.