Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
| Software | From | Fixed in |
|---|---|---|
| kde / konqueror | 3.3.1 | 3.3.1.x |
| kde / kdelibs | 3.1.5 | 3.1.5.x |
| kde / kdelibs | 3.1.3 | 3.1.3.x |
| kde / kdelibs | 3.2.2 | 3.2.2.x |
| kde / kdelibs | 3.2.1 | 3.2.1.x |
| kde / kdelibs | 3.1 | 3.1.x |
| kde / kdelibs | 3.1.2 | 3.1.2.x |
| kde / kdelibs | 3.1.4 | 3.1.4.x |
| kde / kdelibs | 3.1.1 | 3.1.1.x |
| kde / kdelibs | 3.2 | 3.2.x |