Oval Definition:oval:com.redhat.rhsa:def:20060582
Revision Date:2008-03-20Version:640
Title:RHSA-2006:0582: kdebase security fix (Low)
Description:The kdebase packages provide the core applications for KDE, the K Desktop Environment. These core packages include the file manager Konqueror.

  • Ilja van Sprundel discovered a lock file handling flaw in kcheckpass. If the directory /var/lock is writable by a user who is allowed to run kcheckpass, that user could gain root privileges. In Red Hat Enterprise Linux, the /var/lock directory is not writable by users and therefore this flaw could only have been exploited if the permissions on that directory have been badly configured. A patch to block this issue has been included in this update. (CVE-2005-2494)

    The following bugs have also been addressed:

    - kstart --tosystray does not send the window to the system tray in Kicker

    - When the customer enters or selects URLs in Firefox's address field, the desktop freezes for a couple of seconds

    - fish kioslave is broken on 64-bit systems

    All users of kdebase should upgrade to these updated packages, which contain patches to resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2005-2494
    RHSA-2006:0582
    RHSA-2006:0582-01
    RHSA-2006:0582-01
    Platform(s):Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • kdebase is earlier than 6:3.3.1-5.13
  • AND kdebase is signed with Red Hat redhatrelease2 key
  • kdebase-devel is earlier than 6:3.3.1-5.13
  • AND kdebase-devel is signed with Red Hat redhatrelease2 key
  • BACK