Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Slackware 10.0: 2004-247-01 Critical: KDE Frame Injection Issue

slackware
Calendar Grey September 4, 2004
Dist Slackware Esm H88
Enhance the security of kdelibs and kdebase on Slackware to mitigate severe vulnerabilities impacting various editions.
New kdelibs and kdebase packages are available for Slackware 9.1, 10.0, and -current to fix security issues

Summary

Here are the details from the Slackware 10.0 ChangeLog: Fri Sep 3 13:13:09 PDT 2004 patches/packages/kdebase-3.2.3-i486-2.tgz: Patched frame injection vulnerability in Konqueror. For more details, see: https://www.cve.org/CVERecord?id=CAN-2004-0721 (* Security fix *) patches/packages/kdelibs-3.2.3-i486-2.tgz: Patched unsafe temporary directory usage, cross-domain cookie injection vulnerability for certain country specific domains, and frame injection vulnerability in Konqueror. For more details, see: https://www.cve.org/CVERecord?id=CAN-2004-0689 https://www.cve.org/CVERecord?id=CAN-2004-0690 https://www.cve.org/CVERecord?id=CAN-2004-0721 https://www.cve.org/CVERecord?id=CAN-2004-0746 (* Security fix *)

Where Find New Packages

Updated packages for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/kdebase-3.1.4-i486-2.tgz ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/kdelibs-3.1.4-i486-3.tgz
Updated packages for Slackware 10.0:
Updated packages for Slackware -current:

MD5 Signatures

Slackware 9.1 packages: 296fc0b2d31c5914b08ab54332312cf9 kdebase-3.1.4-i486-2.tgz c0de072389daeb6bd8a1cde2ed1dc8ef kdelibs-3.1.4-i486-3.tgz
Slackware 10.0 packages: 528edca97f8d6c412742fa8f817abd76 kdebase-3.2.3-i486-2.tgz 8eabfa597ea805ceb457933d36e144be kdelibs-3.2.3-i486-2.tgz
Slackware -current packages: 528edca97f8d6c412742fa8f817abd76 kdebase-3.2.3-i486-2.tgz 8eabfa597ea805ceb457933d36e144be kdelibs-3.2.3-i486-2.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the packages as root: # upgradepkg kdebase-3.2.3-i486-2.tgz kdelibs-3.2.3-i486-2.tgz

Related News

Your message here