ooo-build-1.9.78.2 has been released
knoda 0.7.3-test2 has been released
OSNews has published a KDE 3.4 Beta 2 preview
Yzis M3 has been released
KDE Security Advisory: Buffer overflow in fliccd of kdeedu/kstars/indi
Original Release Date: 2005-02-15
URL: http://www.kde.org/info/security/advisory-20050215-1.txt
0. References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0011
1. Systems affected:
KDE 3.3 up to including KDE 3.3.2.
Original Release Date: 2005-02-15
URL: http://www.kde.org/info/security/advisory-20050215-1.txt
0. References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0011
1. Systems affected:
KDE 3.3 up to including KDE 3.3.2.
Rosegarden-4 1.0 has been released
amaroK 1.2 has been released
OSDir has posted a screenshot slideshow of KDE 3.4 Beta 2
OpenOffice.org build 1.9.78 has been released
KDE 3.4 Beta 2 has been released
February 9, 2005 (The Internet) - The KDE Project is pleased to announce the immediate availability of KDE 3.4 Beta 2, dubbed "Keinstein".
February 9, 2005 (The Internet) - The KDE Project is pleased to announce the immediate availability of KDE 3.4 Beta 2, dubbed "Keinstein".
KipiPlugins-0.1.0-beta2 and libkipi-0.1.1 are available
digiKam 0.7.2-beta1 is out
DigikamImagePlugins 0.7.2-beta1 has been released
Version 1.2-beta4 of the amaroK audio player has been released
KDE Security Advisory: Multiple vulnerabilities in Konversation
Original Release Date: 20050121
URL: http://www.kde.org/info/security/advisory-20050121-1.txt
0. References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0129
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0130
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0131
http://lists.netsys.com/pipermail/full-disclosure/2005-January/031033.html
1. Systems affected:
All Konversation versions up to and including 0.15
Original Release Date: 20050121
URL: http://www.kde.org/info/security/advisory-20050121-1.txt
0. References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0129
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0130
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0131
http://lists.netsys.com/pipermail/full-disclosure/2005-January/031033.html
1. Systems affected:
All Konversation versions up to and including 0.15
KDE Security Advisory: KOffice PDF Import Filter Vulnerability
Original Release Date: 2005-01-20
URL: http://www.kde.org/info/security/advisory-20050120-1.txt
0. References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0064
http://www.idefense.com/application/poi/display?id=186&type=vulnerabilities
1. Systems affected:
KOffice 1.3 up to including KOffice 1.3.5
2. Overview:
The KOffice PDF Import Filter shares code with xpdf. xpdf contains a buffer overflow that can be triggered by a specially crafted PDF file.
Original Release Date: 2005-01-20
URL: http://www.kde.org/info/security/advisory-20050120-1.txt
0. References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0064
http://www.idefense.com/application/poi/display?id=186&type=vulnerabilities
1. Systems affected:
KOffice 1.3 up to including KOffice 1.3.5
2. Overview:
The KOffice PDF Import Filter shares code with xpdf. xpdf contains a buffer overflow that can be triggered by a specially crafted PDF file.
KDE Security Advisory: kpdf Buffer Overflow Vulnerability
Original Release Date: 2005-01-19
URL: http://www.kde.org/info/security/advisory-20050119-1.txt
0. References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0064
http://www.idefense.com/application/poi/display?id=186&type=vulnerabilities
1. Systems affected:
KDE 3.2 up to including KDE 3.2.3.
KDE 3.3 up to including KDE 3.3.2.
Original Release Date: 2005-01-19
URL: http://www.kde.org/info/security/advisory-20050119-1.txt
0. References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0064
http://www.idefense.com/application/poi/display?id=186&type=vulnerabilities
1. Systems affected:
KDE 3.2 up to including KDE 3.2.3.
KDE 3.3 up to including KDE 3.3.2.
The third release in the 1.3 series of the KDE Disk archiver (KDar) has been released
KDE 3.4 Beta 1 has been released
KDE Security Advisory: ftp kioslave command injection
Original Release Date: 2005-01-01
URL: http://www.kde.org/info/security/advisory-20050101-1.txt
0. References
http://www.securityfocus.com/bid/11827 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1165
1. Systems affected:
All KDE releases up to including KDE 3.3.2.
2. Overview:
KDE applications which use the ftp kioslave, e.g. Konqueror, allow remote attackers to execute arbitrary FTP commands via an ftp://URL that contains an URL-encoded newline ( %0a ) before the ftp command, which causes the commands to be inserted into the resulting FTP session.
Due to similiarities between the ftp and the SMTP protocol, this vulnerability allows to misuse the ftp slave to connect to a SMTP server and issue arbitrary commands, like sending an email.
Original Release Date: 2005-01-01
URL: http://www.kde.org/info/security/advisory-20050101-1.txt
0. References
http://www.securityfocus.com/bid/11827 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1165
1. Systems affected:
All KDE releases up to including KDE 3.3.2.
2. Overview:
KDE applications which use the ftp kioslave, e.g. Konqueror, allow remote attackers to execute arbitrary FTP commands via an ftp://URL that contains an URL-encoded newline ( %0a ) before the ftp command, which causes the commands to be inserted into the resulting FTP session.
Due to similiarities between the ftp and the SMTP protocol, this vulnerability allows to misuse the ftp slave to connect to a SMTP server and issue arbitrary commands, like sending an email.