Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 10: KIO KSSL Security Issue Advisory For KDE 4.3.1

fedora
Calendar Grey September 15, 2009
Dist Fedora Esm H88
The update for Fedora 10 featuring KDE 4.3.1 brings several bug repairs along with addressing a possible vulnerability in KIO KSSL.
This updates KDE to 4.3.1, the latest upstream bugfix release

Summary

KDE libraries with experimental or unstable api/abi.

Update Information:

This updates KDE to 4.3.1, the latest upstream bugfix release. The main improvements are: * KDE 4.3 is now also available in Croatian. * A crash when editing toolbar setup has been fixed. * Support for transferring files through SSH using KIO::Fish has been fixed. * A number of bugs in KWin, KDE's window and compositing manager has been fixed. * A large number of bugs in KMail, KDE's email client are now gone. See https://kde.org/announcements/announce-4.3.1/ for more information. In addition, this update: * fixes a potential security issue (CVE-2009-2702) with certificate validation in the KIO KSSL code. It is believed that the affected code is not actually used (the code in Qt, for which a security update was already issued, is) and thus the issue is only potential, but KSSL is being patched just in case, * splits PolicyKit-kde out of kdebase-workspace again to avoid forcing it onto GNOME-based setups, where PolicyKit-gnome is desired instead (#519654).

Change Log

References


[ 1 ] Bug #520661 - CVE-2009-2702 kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName https://bugzilla.redhat.com/show_bug.cgi?id=520661

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update kdelibs-experimental' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: kdelibs-experimental
Product: Fedora 10
Version: 4.3.1
Release: 1.fc10
Summary: KDE libraries with experimental or unstable api/abi

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here