Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Apple Seeds First OS X 10.8.5 Beta to Developers
· Microsoft will pay up to $100K for new Windows exploit techniques
· DSA 2711-1: haproxy security update
· System Builder Marathon, Q2 2013 and more
· Microsoft delivers biggest update to date to TypeScript
· Tiff/nss-pam-ldapd Updates for Debian
· Update for Windows 8/Server 2012
· Apple TV 5.4 beta adds iTunes Radio, Conference Room Display
· DSA 2710-1: xml-security-c security update
· Intel DZ87KLT-75K Kinsley Thunderbolt Motherboard Review

Upcoming News
· EVGA GeForce GTX 780 ACX SC Review @ Hardware Canucks
· MSI FM2-A85XMA-E35 Micro ATX Motherboard Review @ HiTech Legion
· Thermaltake Urban S31 Chassis Review
· [RHSA-2013:0957-01] Critical: java-1.7.0-openjdk security update
· [RHSA-2013:0958-01] Important: java-1.7.0-openjdk security update
· Kingston HyperX Beast Black 16 GB 2133 C11 (2x8 GB) @ techPowerUp
· Canon PowerShot N Review @ TechReviewSource.com
· Gunpoint Review (PC)
· E3 2013: Wrap Up Coverage @ Legit Reviews
· Cougar Spike Micro ATX Case @ LanOC Reviews

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Building a new PC: how EXACTLY to install USB mouse?
by: joyask43
on: 2013-06-09 14:36
6 replies, 2675 views

· Packet CD
by: natalieksh5
on: 2013-06-06 14:19
4 replies, 3455 views

· THE SIMS 2 DIRECTX 9.0C ERROR MESSAGE!! HELP! URGENT!!
by: tandrask34
on: 2013-06-05 14:06
28 replies, 93240 views

· Hello
by: barryherne
on: 2013-06-05 13:09
0 replies, 185 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6900 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » March 2005 » MDKSA-2005:058 - Updated kdelibs packages

MDKSA-2005:058 - Updated kdelibs packages

Posted by Philipp Esselbach on: 03/17/2005 04:44 AM [ Print | 0 comment(s) ]

Updated kdelibs packages are available for Mandrakelinux
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: kdelibs
Advisory ID: MDKSA-2005:058
Date: March 16th, 2005

Affected versions: 10.0, 10.1, Corporate 3.0
______________________________________________________________________

Problem Description:

A vulnerability in dcopserver was discovered by Sebastian Krahmer of the SUSE security team. A local user can lock up the dcopserver of other users on the same machine by stalling the DCOP authentication process, causing a local Denial of Service. dcopserver is the KDE Desktop Communication Procotol daemon (CAN-2005-0396).

As well, the IDN (International Domain Names) support in Konqueror is vulnerable to a phishing technique known as a Homograph attack. This attack is made possible due to IDN allowing a website to use a wide range of international characters that have a strong resemblance to other characters. This can be used to trick users into thinking they are on a different trusted site when they are in fact on a site mocked up to look legitimate using these other characters, known as homographs. This can be used to trick users into providing personal information to a site they think is trusted (CAN-2005-0237).

Finally, it was found that the dcopidlng script was vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files of a user when the script is run on behalf of that user. However, this script is only used as part of the build process of KDE itself and may also be used by the build processes of third- party KDE applications (CAN-2005-0365).

The updated packages are patched to deal with these issues and Mandrakesoft encourages all users to upgrade immediately.




_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0237
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0365
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0396
http://www.kde.org/info/security/advisory-20050316-1.txt
http://www.kde.org/info/security/advisory-20050316-2.txt
http://www.kde.org/info/security/advisory-20050316-3.txt
______________________________________________________________________

Updated Packages:

Mandrakelinux 10.0:
6c24906717a7a75fb7c0c7b0267bdca6 10.0/RPMS/kdelibs-common-3.2-36.12.100mdk.i586.rpm
e0cb970bc7efeb6ba447c6cd92398f4b 10.0/RPMS/libkdecore4-3.2-36.12.100mdk.i586.rpm
046bd58e4261238bb8857d3bdd5e09e7 10.0/RPMS/libkdecore4-devel-3.2-36.12.100mdk.i586.rpm
113483436cc05765978f497ba70c300a 10.0/SRPMS/kdelibs-3.2-36.12.100mdk.src.rpm

Mandrakelinux 10.0/AMD64:
23bd80fb1b6e29ac30abf8ca030f02ce amd64/10.0/RPMS/kdelibs-common-3.2-36.12.100mdk.amd64.rpm
f0ed5a6cc839264cb1cf3d6a83a4881a amd64/10.0/RPMS/lib64kdecore4-3.2-36.12.100mdk.amd64.rpm
a1985658ba14f572ba759482debcef14 amd64/10.0/RPMS/lib64kdecore4-devel-3.2-36.12.100mdk.amd64.rpm
113483436cc05765978f497ba70c300a amd64/10.0/SRPMS/kdelibs-3.2-36.12.100mdk.src.rpm

Mandrakelinux 10.1:
ec7b57ea845f6c7ab01c8ee67b14b473 10.1/RPMS/kdelibs-common-3.2.3-104.2.101mdk.i586.rpm
9e900e767495f30a02453974855b0497 10.1/RPMS/libkdecore4-3.2.3-104.2.101mdk.i586.rpm
036ba66a047006933c33bc397d9503ee 10.1/RPMS/libkdecore4-devel-3.2.3-104.2.101mdk.i586.rpm
468a28ffcb57e01535ba35fb633f4ee5 10.1/SRPMS/kdelibs-3.2.3-104.2.101mdk.src.rpm

Mandrakelinux 10.1/X86_64:
2f0b1d547f7b8f0234606092b3ea2bd4 x86_64/10.1/RPMS/kdelibs-common-3.2.3-104.2.101mdk.x86_64.rpm
96cc9a12ab7c247f2c7c0c478fd3c772 x86_64/10.1/RPMS/lib64kdecore4-3.2.3-104.2.101mdk.x86_64.rpm
cbe167d1624f0a1821de6af47b734771 x86_64/10.1/RPMS/lib64kdecore4-devel-3.2.3-104.2.101mdk.x86_64.rpm
9e900e767495f30a02453974855b0497 x86_64/10.1/RPMS/libkdecore4-3.2.3-104.2.101mdk.i586.rpm
468a28ffcb57e01535ba35fb633f4ee5 x86_64/10.1/SRPMS/kdelibs-3.2.3-104.2.101mdk.src.rpm

Corporate 3.0:
21a462267a1e459b2fe234338667d3c5 corporate/3.0/RPMS/kdelibs-common-3.2-36.12.C30mdk.i586.rpm
221807f377f57439960bdcdfa4ea4a5c corporate/3.0/RPMS/libkdecore4-3.2-36.12.C30mdk.i586.rpm
b6b4538be00036dca0b983aa55061fb8 corporate/3.0/RPMS/libkdecore4-devel-3.2-36.12.C30mdk.i586.rpm
f8bb656cb23100dae5da6c7024f89277 corporate/3.0/SRPMS/kdelibs-3.2-36.12.C30mdk.src.rpm

Corporate 3.0/X86_64:
d42efc7c072d78794750742a0ffa8808 x86_64/corporate/3.0/RPMS/kdelibs-common-3.2-36.12.C30mdk.x86_64.rpm
ed57b05ddc173abc8271516abd47e289 x86_64/corporate/3.0/RPMS/lib64kdecore4-3.2-36.12.C30mdk.x86_64.rpm
99bd9de3205bf4e728987b1267382174 x86_64/corporate/3.0/RPMS/lib64kdecore4-devel-3.2-36.12.C30mdk.x86_64.rpm
f8bb656cb23100dae5da6c7024f89277 x86_64/corporate/3.0/SRPMS/kdelibs-3.2-36.12.C30mdk.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandrakesoft for security. You can obtain the GPG public key of the Mandrakelinux Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandrakelinux at:

http://www.mandrakesoft.com/security/advisories

If you want to report vulnerabilities, please contact

security_linux-mandrake.com


Bookmark and Share

« MDKSA-2005:059 - Updated evolution packages · libgtk-java 2.6.1 »

Linux Compatible » News » March 2005 » MDKSA-2005:058 - Updated kdelibs packages
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition