Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 10 kdelibs3 Critical Advisory: SSL Certificate Validation Bug

fedora
Calendar Grey September 8, 2009
Dist Fedora Esm H88
Resolves a problem related to the validation of SSL certificates within the kdelibs3 libraries for Fedora 10, specifically addressing the kdelibs3-3.5.10-13 version.
This update fixes CVE-2009-2702, a security issue where SSL certificates containing embedded NUL characters would falsely pass validation when they're actually invalid, for the KD...

Summary

Libraries for the K Desktop Environment 3:

KDE Libraries included: kdecore (KDE core library), kdeui (user interface),

kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking),

kspell (spelling checker), jscript (javascript), kab (addressbook),

kimgio (image manipulation).

Update Information:

This update fixes CVE-2009-2702, a security issue where SSL certificates containing embedded NUL characters would falsely pass validation when they're actually invalid, for the KDE 3 compatibility version of kdelibs.

Change Log

* Sun Sep 6 2009 Kevin Kofler - 3.5.10-13.1 - fix for CVE-2009-2702 * Sun Jul 26 2009 Kevin Kofler - 3.5.10-13 - fix CVE-2009-2537 - select length DoS - fix CVE-2009-1725 - crash, possible ACE in numeric character references - fix CVE-2009-1690 - crash, possible ACE in KHTML ( use-after-free) - fix CVE-2009-1687 - possible ACE in KJS (FIXME: still crashes?) - fix CVE-2009-1698 - crash, possible ACE in CSS style attribute handling * Fri Jul 24 2009 Fedora Release Engineering - 3.5.10-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Sat Jul 18 2009 Rex Dieter - 3.5.10-12 - FTBFS kdelibs3-3.5.10-11.fc11 (#511571) - -devel: Requires: %{name}%_isa ... * Sun Apr 19 2009 Rex Dieter - 3.5.10-11 - update openssl patch (for 0.9.8k) * Thu Apr 16 2009 Rex Dieter - 3.5.10-10 - move designer plugins to runtime (#487622) - make -apidocs noarch * Mon Mar 2 2009 Than Ngo - 3.5.10-9 - enable -apidocs * Fri Feb 27 2009 Rex Dieter - 3.5.10-8 - disable -apidocs (f11+, #487719) - cleanup unused kdeui_symlink hack baggage * Wed Feb 25 2009 Than Ngo - 3.5.10-7 - fix files conflicts with 4.2.x - fix build issue with gcc-4.4 * Wed Feb 25 2009 Fedora Release Engineering - 3.5.10-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Sat Jan 31 2009 Rex Dieter - 6:3.5.10-5 - unowned dirs (#483318) * Sat Jan 10 2009 Ville Skyttä - 6:3.5.10-4 - Slight speedup to profile.d/kde.sh (#465370). * Mon Dec 15 2008 Kevin Kofler 3.5.10-3 - update the KatePart latex.xml syntax definition to the version from Kile 2.0.3 * Thu Dec 4 2008 Rex Dieter 3.5.10-2 - omit libkscreensaver (F9+)

References


[ 1 ] Bug #520661 - CVE-2009-2702 kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName https://bugzilla.redhat.com/show_bug.cgi?id=520661

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update kdelibs3' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: kdelibs3
Product: Fedora 10
Version: 3.5.10
Release: 13.fc10.1
Summary: K Desktop Environment 3 - Libraries

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here