KDE 1716 Published by Philipp Esselbach 0

A kdelibs update for Gentoo Linux is available

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200408-23
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Low
Title: kdelibs: Cross-domain cookie injection vulnerability
Date: August 24, 2004
Bugs: #61389
ID: 200408-23

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
=======

The cookie manager component in kdelibs contains a vulnerability allowing an attacker to potentially gain access to a user's session on a legitimate web server.

KDE 1716 Published by Philipp Esselbach 0

Release 2.3.1 of Rekall, the database front end for KDE (and QT) is now available

KDE 1716 Published by Philipp Esselbach 0

KDbg 1.9.6 (development series, beta stage) has been released

KDE 1716 Published by Philipp Esselbach 0

Three security advisories have been issued today for KDE.

The first advisory concerns the unsafe handling of KDE's temporary directory in certain circumstances. The second advisory relates to the unsafe creation of temporary files by KDE 3.2.x's dcopserver . The third advisory is about a frame injection vulnerability in Konqueror as earlier reported by Heise Online and Secunia

Distributions are expected to have updated binary packages available shortly. All issues mentioned above have also been fixed in the KDE 3.3 Release Candidate 2 that was announced yesterday . The final release of KDE 3.3 is expected later this month.