Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Latest stable upstream release, includes security fix for CVE-2017-5593. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-40d29c8e84 2017-02-23 14:52:56.160315 -------------------------------------------------------------------------------- Name : kopete Product : Fedora 24 Version : 16.12.2 Release : 2.fc24 URL : Summary : Instant messenger Description : Instant messenger. -------------------------------------------------------------------------------- Update Information: Latest stable upstream release, includes security fix for CVE-2017-5593 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1421069 - CVE-2017-5593 psi-plus: User impersonation vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1421069 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade kopete' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Latest stable upstream release, includes security fix for CVE-2017-5593. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-3fb57530fb 2017-02-23 14:53:55.960773 -------------------------------------------------------------------------------- Name : kopete Product : Fedora 25 Version : 16.12.2 Release : 2.fc25 URL : Summary : Instant messenger Description : Instant messenger. -------------------------------------------------------------------------------- Update Information: Latest stable upstream release, includes security fix for CVE-2017-5593 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1421069 - CVE-2017-5593 psi-plus: User impersonation vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1421069 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade kopete' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Multiple integer overflow flaws were found in the way Kopete processes Gadu-Gadu messages. A remote attacker could send a specially crafted Gadu-Gadu message which would cause Kopete to crash or possibly execute arbitrary code.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-624 2005-07-22 ---------------------------------------------------------------------Product : Fedora Core 4 Name : kdenetwork Version : 3.4.1 Release : 0.fc4.2 Summary : K Desktop Environment - Network Applications Description : Networking applications for the K Desktop Environment. ---------------------------------------------------------------------Update Information: Multiple integer overflow flaws were found in the way Kopete processes Gadu-Gadu messages. A remote attacker could send a specially crafted Gadu-Gadu message which would cause Kopete to crash or possibly execute arbitrary code. The Common Vulnerabilities and Exposures project assigned the name CAN-2005-1852 to this issue. Users of Kopete should update to these packages which contain a patch to correct this issue. ---------------------------------------------------------------------* Thu Jul 21 2005 Than Ngo 7:3.4.1-0.fc4.2 - fix crash in kopete - apply patch to fix libgadu vulnerabilities #163811, CVE CAN-2005-1852 thank to kde security team ---------------------------------------------------------------------This update can be downloaded from: 4e3db27303568ad94e65d82ffd1189f9 SRPMS/kdenetwork-3.4.1-0.fc4.2.src.rpm fb065037fb526cd9bb933c3c076a9dec ppc/kdenetwork-3.4.1-0.fc4.2.ppc.rpm 1b26b336de353a59dd7dffe5816e0951 ppc/kdenetwork-devel-3.4.1-0.fc4.2.ppc.rpm 971510423874ce1b9339a9989044f194 ppc/debug/kdenetwork-debuginfo-3.4.1-0.fc4.2.ppc.rpm ecd5ecaf2c3b2de2b9d1997f71d37183 x86_64/kdenetwork-3.4.1-0.fc4.2.x86_64.rpm 98e9c1a88792e0df169887f669608fa6 x86_64/kdenetwork-devel-3.4.1-0.fc4.2.x86_64.rpm 4d189d1a3c8c2abe037c9254a3cffeb8 x86_64/debug/kdenetwork-debuginfo-3.4.1-0.fc4.2.x86_64.rpm 54fd9578f7ab23e8d35d7e85e1b3e493 i386/kdenetwork-3.4.1-0.fc4.2.i386.rpm 12b717074ad81ed6c120d028684c3e6f i386/kdenetwork-devel-3.4.1-0.fc4.2.i386.rpm d1b78acac0474698c261d117ce9832c7 i386/debug/kdenetwork-debuginfo-3.4.1-0.fc4.2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands.. - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200305-03 - - - --------------------------------------------------------------------- PACKAGE : kopete SUMMARY : Unsafe command line cleansing DATE : 2003-05-14 07:39 UTC EXPLOIT : remote VERSIONS AFFECTED : =kopete-0.6.2 CVE : CAN-2003-0256 - - - --------------------------------------------------------------------- The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands. SOLUTION It is recommended that all Gentoo Linux users who are running net-im/kopete upgrade to kopete-0.6.2 as follows: emerge sync emerge kopete emerge clean - - - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.