Kommander: Insecure remote script execution — GLSA 200504-23 Kommander executes remote scripts without confirmation, potentially resulting in the execution of arbitrary code. Affected packages Package kde-base/kdewebdev on all architectures Affected versions < 3.3.2-r2 Unaffected versions >= 3.3.2-r2 Background KDE is a feature-rich graphical desktop environment for Linux and Unix-like Operating Systems. Kommander is a visual dialog editor and interpreter for KDE applications, part of the kdewebdev package. Description Kommander executes data files from possibly untrusted locations without user confirmation. Impact An attacker could exploit this to execute arbitrary code with the permissions of the user running Kommander. Workaround There is no known workaround at this time. Resolution All kdewebdev users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=kde-base/kdewebdev-3.3.2-r2" References CAN-2005-0754 KDE Security Advisory: Kommander untrusted code execution