Description: | Description:
The remote host is missing updates announced in advisory RHSA-2005:009.
The kdelibs packages include libraries for the K Desktop Environment. The kdebase packages include core applications for the K Desktop Environment.
Secunia Research discovered a window injection spoofing vulnerability affecting the Konqueror web browser. This issue could allow a malicious website to show arbitrary content in a different browser window. The Common Vulnerabilities and Exposures project has assigned the name CVE-2004-1158 to this issue.
A bug was discovered in the way kioslave handles URL-encoded newline (%0a) characters before the FTP command. It is possible that a specially crafted URL could be used to execute any ftp command on a remote server, or potentially send unsolicited email. The Common Vulnerabilities and Exposures project has assigned the name CVE-2004-1165 to this issue.
A bug was discovered that can crash KDE screensaver under certain local circumstances. This could allow an attacker with physical access to the workstation to take over a locked desktop session. Please note that this issue only affects Red Hat Enterprise Linux 2.1. The Common Vulnerabilities and Exposures project has assigned the name CVE-2005-0078 to this issue.
All users of KDE are advised to upgrade to this updated packages, which contain backported patches to correct these issues.
Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date
http://rhn.redhat.com/errata/RHSA-2005-009.html http://www.kde.org/info/security/advisory-20041213-1.txt http://www.kde.org/info/security/advisory-20050101-1.txt http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1158 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1165 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0078
Risk factor : High
CVSS Score: 7.5
|