Oval Definition:oval:com.redhat.rhsa:def:20050065
Revision Date:2005-02-15Version:502
Title:RHSA-2005:065: kdelibs security update (Important)
Description:The kdelibs packages include libraries for the K Desktop Environment.

Two flaws were found in the sandbox environment used to run Java-applets in the Konqueror web browser. If a user has Java enabled in Konqueror and visits a malicious website, the website could run a carefully crafted Java-applet and obtain escalated privileges allowing reading and writing of arbitrary files with the privileges of the victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1145 to this issue.

A flaw was discovered in the FTP kioslave. KDE applications such as Konqueror could be forced to execute arbitrary FTP commands via a carefully crafted ftp URL. The URL could also be crafted in such a way as to send an arbitrary email via SMTP. An attacker could make use of this flaw if a victim visits a malicious web site. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-1165 to this issue.

Users should update to these erratum packages which contain backported patches to correct these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2004-1145
CVE-2004-1165
RHSA-2005:065-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 4 is installed
  • AND Package Information
  • kdelibs is earlier than 6:3.3.1-3.3
  • AND kdelibs is signed with Red Hat master key
  • OR
  • kdelibs-devel is earlier than 6:3.3.1-3.3
  • AND kdelibs-devel is signed with Red Hat master key
  • BACK