Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Debian Kdelibs 361-1 Moderate: Remote Access And Credential Leak Fix

debian
Calendar Grey August 1, 2003
Scroller Debian
Update your Debian kdelibs package to prevent remote access and credential leaks by applying the latest security fixes.
Potential unauthorized access and man-in-the-middle attacks have been fixed.

Summary

Two vulnerabilities were discovered in kdelibs:

- CAN-2003-0459: KDE Konqueror for KDE 3.1.2 and earlier does not
remove authentication credentials from URLs of the
"user:password@host" form in the HTTP-Referer header, which could
allow remote web sites to steal the credentials for pages that link
to the sites.

- CAN-2003-0370: Konqueror Embedded and KDE 2.2.2 and earlier does not
validate the Common Name (CN) field for X.509 Certificates, which
could allow remote attackers to spoof certificates via a
man-in-the-middle attack.

These vulnerabilities are described in the following security
advisories from KDE:

https://kde.org/info/security/advisory-20030729-1.txt
https://kde.org/info/security/advisory-20030602-1.txt

For the current stable distribution (woody) these problems have been
fixed in version 2.2.2-13.woody.8.

For the unstable distribution (sid) these problems have been fixed in
version 4:3.1.3-1.

We recommend that you update your kdelibs package.

Upgrade Instructions
------------...

Read the Full Advisory

Package: kdelibs

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.