Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Fedora: FEDORA-2004-293 Severe: Kdebase Multiple Issues

fedora
Calendar Grey September 8, 2004
Dist Fedora Esm H88
Secure your KDE on Fedora Core 2 by backing up, updating packages, applying patches, reconfiguring settings, and monitoring updates regularly for safety
Several KDE vulnerabilities.

Summary

Core applications for the K Desktop Environment. Included are: kdm

(replacement for xdm), kwin (window manager), konqueror (filemanager,

web browser, ftp client, ...), konsole (xterm replacement), kpanel

(application starter and desktop pager), kaudio (audio server),

kdehelp (viewer for kde help files, info and man pages), kthememgr

(system for managing alternate theme packages) plus other KDE

components (kcheckpass, kikbd, kscreensaver, kcontrol, kfind,

kfontmanager, kmenuedit).

Update Information:

Andrew Tuitt reported that versions of KDE up to and including 3.2.3 create temporary directories with predictable names. A local attacker could prevent KDE applications from functioning correctly, or overwrite files owned by other users by creating malicious symlinks. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0689 to this issue.

WESTPOINT internet reconnaissance services has discovered that the KDE web browser Konqueror allows websites to set cookies for certain country specific secondary top level domains. An attacker within one of the affected domains could construct a cookie which would be sent to all other websites within the domain leading to a session fixation attack. This issue does not affect popular domains such as .co.uk, .co.in, or .com. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0721 to this issue.

A frame injection spoofing vulnerability has been discovered in the Konqueror web browser. This iss...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2004-293 2004-09-08
Product : Fedora Core 2 Name : kdebase Version : 3.2.2 Release : 6.FC2 Summary : K Desktop Environment - core files Description : Core applications for the K Desktop Environment. Included are: kdm (replacement for xdm), kwin (window manager), konqueror (filemanager, web browser, ftp client, ...), konsole (xterm replacement), kpanel (application starter and desktop pager), kaudio (audio server), kdehelp (viewer for kde help files, info and man pages), kthememgr (system for managing alternate theme packages) plus other KDE components (kcheckpass, kikbd, kscreensaver, kcontrol, kfind, kfontmanager, kmenuedit).

Update Instructions

Product: Fedora Core 2
Name: kdebase
Version: 3.2.2
Release: 6.FC2
Summary: K Desktop Environment - core files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here