Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora: kdelibs Update Notification, Critical: Session Fixation Threat

fedora
Calendar Grey September 8, 2004
Dist Fedora Esm H88
Several security flaws detected in Fedora's kdelibs affecting KDE libraries' operations. Performing an upgrade is highly recommended to mitigate possible risks.
Several KDE vulnerabilities.

Summary

Libraries for the K Desktop Environment:

KDE Libraries included: kdecore (KDE core library), kdeui (user interface),

kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking),

kspell (spelling checker), jscript (javascript), kab (addressbook),

kimgio (image manipulation).

Update Information:

Andrew Tuitt reported that versions of KDE up to and including 3.2.3 create temporary directories with predictable names. A local attacker could prevent KDE applications from functioning correctly, or overwrite files owned by other users by creating malicious symlinks. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0689 to this issue.

WESTPOINT internet reconnaissance services has discovered that the KDE web browser Konqueror allows websites to set cookies for certain country specific secondary top level domains. An attacker within one of the affected domains could construct a cookie which would be sent to all other websites within the domain leading to a session fixation attack. This issue does not affect popular domains such as .co.uk, .co.in, or .com. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0721 to this issue.

A frame injection spoofing vulnerability has been discovered in the Konqueror web browser. This iss...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2004-290 2004-09-08
Product : Fedora Core 1 Name : kdelibs Version : 3.1.4 Release : 7 Summary : K Desktop Environment - Libraries Description : Libraries for the K Desktop Environment: KDE Libraries included: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation).

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora Core 1
Name: kdelibs
Version: 3.1.4
Release: 7
Summary: K Desktop Environment - Libraries

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here