Version: (using KDE Devel) Installed from: Compiled sources A short glance at the latest version (1.10) of file kdebase/kioslave/thumbnail/gscreator.cpp revealed two problems: - gs should be called with option -dSAFER, otherwise malicious PostScript files can delete, rename and overwrite files. This bug is present in the 3.0 branch as well, see my patch for bug 45001 for a fix. - the paths for executables /usr/bin/gs and /usr/bin/dvips are hardcoded. There are lots of systems where neither live in /usr/bin, so this should at least be configurable.
See also kghostview's bug ID 56808 ("Security hole (-dPARANOIDSAFER not used) allows arbitrary command execution").
Forwarded to security@kde.org
Fixed by KDE Security update in 3.0.5b / 3.1.1a of today.
*** Bug 56808 has been marked as a duplicate of this bug. ***