Oval Definition:oval:com.redhat.rhsa:def:20060720
Revision Date:2006-10-18Version:638
Title:RHSA-2006:0720: kdelibs security update (Critical)
Description:The kdelibs package provides libraries for the K Desktop Environment (KDE). Qt is a GUI software toolkit for the X Window System.

  • An integer overflow flaw was found in the way Qt handled pixmap images. The KDE khtml library uses Qt in such a way that untrusted parameters could be passed to Qt, triggering the overflow. An attacker could for example create a malicious web page that when viewed by a victim in the Konqueror browser would cause Konqueror to crash or possibly execute arbitrary code with the privileges of the victim. (CVE-2006-4811)

    Users of KDE should upgrade to these updated packages, which contain a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-4811
    RHSA-2006:0720
    RHSA-2006:0720-01
    RHSA-2006:0720-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • kdelibs is earlier than 6:3.1.3-6.12
  • AND kdelibs is signed with Red Hat master key
  • kdelibs-devel is earlier than 6:3.1.3-6.12
  • AND kdelibs-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • kdelibs-devel is earlier than 6:3.3.1-6.RHEL4
  • AND kdelibs-devel is signed with Red Hat master key
  • kdelibs is earlier than 6:3.3.1-6.RHEL4
  • AND kdelibs is signed with Red Hat master key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • kdelibs is earlier than 6:3.1.3-6.12
  • AND kdelibs is signed with Red Hat master key
  • kdelibs-devel is earlier than 6:3.1.3-6.12
  • AND kdelibs-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • kdelibs is earlier than 6:3.3.1-6.RHEL4
  • AND kdelibs is signed with Red Hat master key
  • kdelibs-devel is earlier than 6:3.3.1-6.RHEL4
  • AND kdelibs-devel is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • kdelibs is earlier than 6:3.3.1-6.RHEL4
  • AND kdelibs is signed with Red Hat redhatrelease2 key
  • kdelibs-devel is earlier than 6:3.3.1-6.RHEL4
  • AND kdelibs-devel is signed with Red Hat redhatrelease2 key
  • BACK