Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Fedora Core 2: 2004-291 Moderate: kde Frame Injection and Cookie Issues

fedora
Calendar Grey September 8, 2004
Dist Fedora Esm H88
Examine several vulnerabilities within the KDE desktop environment that were addressed with backported patches tailored for Fedora Core 2. Ensure to stay updated on mitigating measures.
Several KDE vulnerabilities.

Summary

Libraries for the K Desktop Environment:

KDE Libraries included: kdecore (KDE core library), kdeui (user interface),

kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking),

kspell (spelling checker), jscript (javascript), kab (addressbook),

kimgio (image manipulation).

Update Information:

Andrew Tuitt reported that versions of KDE up to and including 3.2.3 create temporary directories with predictable names. A local attacker could prevent KDE applications from functioning correctly, or overwrite files owned by other users by creating malicious symlinks. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0689 to this issue.

WESTPOINT internet reconnaissance services has discovered that the KDE web browser Konqueror allows websites to set cookies for certain country specific secondary top level domains. An attacker within one of the affected domains could construct a cookie which would be sent to all other websites within the domain leading to a session fixation attack. This issue does not affect popular domains such as .co.uk, .co.in, or .com. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0721 to this issue.

A frame injection spoofing vulnerability has been discovered in the Konqueror web browser. This iss...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2004-291 2004-09-08
Product : Fedora Core 2 Name : kdelibs Version : 3.2.2 Release : 8.FC2 Summary : K Desktop Environment - Libraries Description : Libraries for the K Desktop Environment: KDE Libraries included: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation).

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora Core 2
Name: kdelibs
Version: 3.2.2
Release: 8.FC2
Summary: K Desktop Environment - Libraries

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here