Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 10: 2009-9427 Moderate: KIO KSSL Certificate Validation

fedora
Calendar Grey September 15, 2009
Dist Fedora Esm H88
A new Fedora update alert for kdepim-runtime resolves errors and mitigates possible security vulnerabilities regarding KIO KSSL.
This updates KDE to 4.3.1, the latest upstream bugfix release

Summary

KDE PIM Runtime Environment

Update Information:

This updates KDE to 4.3.1, the latest upstream bugfix release. The main improvements are: * KDE 4.3 is now also available in Croatian. * A crash when editing toolbar setup has been fixed. * Support for transferring files through SSH using KIO::Fish has been fixed. * A number of bugs in KWin, KDE's window and compositing manager has been fixed. * A large number of bugs in KMail, KDE's email client are now gone. See https://kde.org/announcements/announce-4.3.1/ for more information. In addition, this update: * fixes a potential security issue (CVE-2009-2702) with certificate validation in the KIO KSSL code. It is believed that the affected code is not actually used (the code in Qt, for which a security update was already issued, is) and thus the issue is only potential, but KSSL is being patched just in case, * splits PolicyKit-kde out of kdebase-workspace again to avoid forcing it onto GNOME-based setups, where PolicyKit-gnome is desired instead (#519654).

Change Log

References


[ 1 ] Bug #520661 - CVE-2009-2702 kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName https://bugzilla.redhat.com/show_bug.cgi?id=520661

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update kdepim-runtime' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: kdepim-runtime
Product: Fedora 10
Version: 4.3.1
Release: 1.fc10
Summary: KDE PIM Runtime Environment

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here