|Category:||Red Hat Local Security Checks|
|Title:||RedHat Security Advisory RHSA-2005:009|
The remote host is missing updates announced in
The kdelibs packages include libraries for the K Desktop Environment. The
kdebase packages include core applications for the K Desktop Environment.
Secunia Research discovered a window injection spoofing vulnerability
affecting the Konqueror web browser. This issue could allow a malicious
website to show arbitrary content in a different browser window. The Common
Vulnerabilities and Exposures project has assigned the name CVE-2004-1158
to this issue.
A bug was discovered in the way kioslave handles URL-encoded newline (%0a)
characters before the FTP command. It is possible that a specially crafted
URL could be used to execute any ftp command on a remote server, or
potentially send unsolicited email. The Common Vulnerabilities and
Exposures project has assigned the name CVE-2004-1165 to this issue.
A bug was discovered that can crash KDE screensaver under certain local
circumstances. This could allow an attacker with physical access to the
workstation to take over a locked desktop session. Please note that this
issue only affects Red Hat Enterprise Linux 2.1. The Common Vulnerabilities
and Exposures project has assigned the name CVE-2005-0078 to this issue.
All users of KDE are advised to upgrade to this updated packages, which
contain backported patches to correct these issues.
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date
Risk factor : High
Common Vulnerability Exposure (CVE) ID: CVE-2004-1158|
BugTraq ID: 11853
Bugtraq: 20041213 KDE Security Advisory: Konqueror Window Injection Vulnerability (Google Search)
SuSE Security Announcement: SUSE-SR:2005:001 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2004-1165
Bugtraq: 20041205 7a69Adv#16 - Konqueror FTP command injection (Google Search)
Debian Security Information: DSA-631 (Google Search)
XForce ISS Database: web-browser-ftp-command-execution(18384)
Common Vulnerability Exposure (CVE) ID: CVE-2005-0078
Debian Security Information: DSA-660 (Google Search)
XForce ISS Database: kdebase-screensaver-security-bypass(19084)
|Copyright||Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com|
|This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.