Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora Core 1 Advisory FEDORA-2004-292 Moderate: KDE Session Issues

fedora
Calendar Grey September 8, 2004
Dist Fedora Esm H88
An important security patch for Ubuntu GNOME 20 significantly improves user session handling and strengthens protections against CSRF and code injection threats.
Several KDE vulnerabilities

Summary

Core applications for the K Desktop Environment. Included are: kdm

(replacement for xdm), kwin (window manager), konqueror (filemanager,

web browser, ftp client, ...), konsole (xterm replacement), kpanel

(application starter and desktop pager), kaudio (audio server),

kdehelp (viewer for kde help files, info and man pages), kthememgr

(system for managing alternate theme packages) plus other KDE

components (kcheckpass, kikbd, kscreensaver, kcontrol, kfind,

kfontmanager, kmenuedit).

Update Information:

Andrew Tuitt reported that versions of KDE up to and including 3.2.3 create temporary directories with predictable names. A local attacker could prevent KDE applications from functioning correctly, or overwrite files owned by other users by creating malicious symlinks. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0689 to this issue.

WESTPOINT internet reconnaissance services has discovered that the KDE web browser Konqueror allows websites to set cookies for certain country specific secondary top level domains. An attacker within one of the affected domains could construct a cookie which would be sent to all other websites within the domain leading to a session fixation attack. This issue does not affect popular domains such as .co.uk, .co.in, or .com. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0721 to this issue.

A frame injection spoofing vulnerability has been discovered in the Konqueror web browser. This iss...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2004-292 2004-09-08
Product : Fedora Core 1 Name : kdebase Version : 3.1.4 Release : 7 Summary : K Desktop Environment - core files Description : Core applications for the K Desktop Environment. Included are: kdm (replacement for xdm), kwin (window manager), konqueror (filemanager, web browser, ftp client, ...), konsole (xterm replacement), kpanel (application starter and desktop pager), kaudio (audio server), kdehelp (viewer for kde help files, info and man pages), kthememgr (system for managing alternate theme packages) plus other KDE components (kcheckpass, kikbd, kscreensaver, kcontrol, kfind, kfontmanager, kmenuedit).

Update Instructions

Product: Fedora Core 1
Name: kdebase
Version: 3.1.4
Release: 7
Summary: K Desktop Environment - core files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here