Oval Definition:oval:com.redhat.rhsa:def:20070905
Revision Date:2007-10-08Version:637
Title:RHSA-2007:0905: kdebase security update (Moderate)
Description:The kdebase packages provide the core applications for KDE, the K Desktop Environment. These core packages include Konqueror, the web browser and file manager.

These updated packages address the following vulnerabilities:

  • Kees Huijgen found a flaw in the way KDM handled logins when autologin and "shutdown with password" were enabled. A local user would have been able to login via KDM as any user without requiring a password. (CVE-2007-4569)

  • Two Konqueror address spoofing flaws were discovered. A malicious web site could spoof the Konqueror address bar, tricking a victim into believing the page was from a different site. (CVE-2007-3820, CVE-2007-4224)

    Users of KDE should upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-3820
    CVE-2007-4224
    CVE-2007-4569
    RHSA-2007:0905
    RHSA-2007:0905-02
    RHSA-2007:0905-02
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • kdebase is earlier than 6:3.3.1-6.el4
  • AND kdebase is signed with Red Hat redhatrelease2 key
  • kdebase-devel is earlier than 6:3.3.1-6.el4
  • AND kdebase-devel is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • kdebase is earlier than 6:3.5.4-15.el5
  • AND kdebase is signed with Red Hat redhatrelease2 key
  • kdebase-devel is earlier than 6:3.5.4-15.el5
  • AND kdebase-devel is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • kdebase is earlier than 6:3.3.1-6.el4
  • AND kdebase is signed with Red Hat master key
  • kdebase-devel is earlier than 6:3.3.1-6.el4
  • AND kdebase-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • kdebase is earlier than 6:3.5.4-15.el5
  • AND kdebase is signed with Red Hat redhatrelease key
  • kdebase-devel is earlier than 6:3.5.4-15.el5
  • AND kdebase-devel is signed with Red Hat redhatrelease key
  • BACK