Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora: 11 FEDORA-2009-9231 Moderate: Qt SSL Certificate Issue

fedora
Calendar Grey September 2, 2009
Dist Fedora Esm H88
A critical update for the Qt toolkit on Fedora addresses a severe SSL vulnerability that may expose users to security risks from man-in-the-middle attacks
security fix for CVE-2009-2700

Summary

Qt is a software toolkit for developing applications.

This package contains base tools, like string, xml, and network

handling.

security fix for CVE-2009-2700

* Mon Aug 31 2009 Than Ngo - 4.5.2-3

- fix for CVE-2009-2700

* Tue Aug 18 2009 Than Ngo - 4.5.2-2

- security fix for CVE-2009-1725

* Tue Aug 18 2009 Rex Dieter 4.5.2-1.2

- kde-qt: 287-qmenu-respect-minwidth

- kde-qt: 0288-more-x-keycodes (#475247)

* Wed Aug 5 2009 Rex Dieter 4.5.2-1.1

- use linker scripts for _debug targets (#510246)

- apply upstream patch to fix issue in Copy and paste

- optimize (icon-mostly) scriptlets

- -x11: Requires(post,postun): /sbin/ldconfig

* Thu Jul 2 2009 Than Ngo - 4.5.2-1

- 4.5.2

* Sat May 30 2009 Rex Dieter - 4.5.1-13

- -doc: Obsoletes: qt-doc < 1:4.5.1-4 (workaround bug #502401)

* Sat May 23 2009 Rex Dieter - 4.5.1-12

- +phonon_internal macro to toggle packaging of qt's phonon (default off)

* Fri May 22 2009 Rex Dieter - 4.5.1-11

- qt-copy-patches-20090522

* Wed May 20 2009 Rex Dieter - 4.5.1-10.2

- full (non-bootstrap) build

* Wed May 20 2009 Rex Dieter - 4.5.1-10.1

- allow for minimal bootstrap build (*cough* arm *cough*)

* Wed May 6 2009 Rex Dieter - 4.5.1-10

- improved kde4_plugins patch, skip expensive/unneeded canonicalPath

* Wed May 6 2009 Rex Dieter - 4.5.1-9

- include kde4 plugin path by default (#498809)

* Mon May 4 2009 Rex Dieter - 4.5.1-8

- fix invalid assumptions about mysql_config --libs (bug #440673)

- fix %files breakage from 4.5.1-5

* Wed Apr 29 2009 Rex Dieter - 4.5.1-7

- -devel: Provides: qt4-devel%{?_isa} ...

* Mon Apr 27 2009 Than Ngo - 4.5.1-6

- drop useless hunk of qt-x11-opensource-src-4.5.1-enable_ft_lcdfilter.patch

* Mon Apr 27 2009 Rex Dieter - 4.5.1-5

- -devel: Provides: *-static for libQtUiTools.a

* Fri Apr 24 2009 Rex Dieter - 4.5.1-4

- qt-doc noarch

- qt-demos, qt-examples (split from -doc)

- (cosmetic) re-order subpkgs in alphabetical order

- drop unused profile.d bits

* Fri Apr 24 2009 Rex Dieter - 4.5.1-3

- enable FT_LCD_FILTER (uses freetype subpixel filters if available at runtime)

* Fri Apr 24 2009 Than Ngo - 4.5.1-2

- apply upstream patch to fix the svg rendering regression

* Thu Apr 23 2009 Than Ngo - 4.5.1-1

- 4.5.1

[ 1 ] Bug #520435 - CVE-2009-2700 Qt: QSslCertificate incorrect verification of SSL certificate with NUL in subjectAltName

https://bugzilla.redhat.com/show_bug.cgi?id=520435

su -c 'yum update qt' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 11
Version: 4.5.2
Release: 3.fc11
Summary: Qt toolkit

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here