[slackware-security] kdelibs (SSA:2004-238-01)

From: Slackware Security Team (security_at_slackware.com)
Date: 05/18/04

  • Next message: Oliver Minack: "Zen Cart login.php SQL Injection Vulnerability"
    Date: Tue, 18 May 2004 00:08:28 -0700 (PDT)
    To: slackware-security@slackware.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    [slackware-security] kdelibs (SSA:2004-238-01)

    New kdelibs packages are available for Slackware 9.0, 9.1 and -current
    to fix security issues with URI handling.

    More details about this issue may be found in the Common
    Vulnerabilities and Exposures (CVE) database:

      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0411

    Here are the details from the Slackware 9.1 ChangeLog:
    +--------------------------+
    Mon May 17 19:31:12 PDT 2004
    patches/packages/kdelibs-3.1.4-i486-2.tgz: Patched URI security
      issues. According to www.kde.org:
        The telnet, rlogin, ssh and mailto URI handlers in KDE do not
        check for '-' at the beginning of the hostname passed, which
        makes it possible to pass an option to the programs started
        by the handlers.
      For more details, see:
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0411
      (* Security fix *)
    +--------------------------+

    Where to find the new packages:
    +-----------------------------+

    Updated package for Slackware 9.0:
    ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/kde/kdelibs-3.1.3a-i386-2.tgz

    Updated package for Slackware 9.1:
    ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/kdelibs-3.1.4-i486-2.tgz

    Updated package for Slackware -current:
    ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/kde/kdelibs-3.2.2-i486-2.tgz

    MD5 signatures:
    +-------------+

    Slackware 9.0 package:
    554873b76b83e345c2c86a9785199fcf kdelibs-3.1.3a-i386-2.tgz

    Slackware 9.1 package:
    4be0192b1c0c246aa947b625eeb6dfd9 kdelibs-3.1.4-i486-2.tgz

    Slackware -current package:
    015a0efcd12fb61b6bf78a10e218c0cd kdelibs-3.2.2-i486-2.tgz

    Installation instructions:
    +------------------------+

    Upgrade the kdelibs package as root:
    # upgradepkg kdelibs-3.1.4-i486-2.tgz

    +-----+

    Slackware Linux Security Team
    http://slackware.com/gpg-key
    security@slackware.com

    +------------------------------------------------------------------------+
    | To leave the slackware-security mailing list: |
    +------------------------------------------------------------------------+
    | Send an email to majordomo@slackware.com with this text in the body of |
    | the email message: |
    | |
    | unsubscribe slackware-security |
    | |
    | You will get a confirmation message back containing instructions to |
    | complete the process. Please do not reply to this email address. |
    +------------------------------------------------------------------------+

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.4 (GNU/Linux)

    iD8DBQFAqbZaakRjwEAQIjMRArN8AKCE/7v7A3W0lmHzsaERd9dPkcgLsgCdFyyF
    7DC3dKBXzxvFkoHcUqzb4p8=
    =FUQf
    -----END PGP SIGNATURE-----


  • Next message: Oliver Minack: "Zen Cart login.php SQL Injection Vulnerability"

    Relevant Pages

    • [slackware-security] sysklogd update (SSA:2004-124-02)
      ... to fix a security issue where a user could cause syslogd to crash. ... Here are the details from the Slackware 9.1 ChangeLog: ... Updated package for Slackware 8.1: ...
      (Bugtraq)
    • [slackware-security] apache (SSA:2004-133-01)
      ... We recommend that sites running Apache upgrade ... Here are the details from the Slackware 9.1 ChangeLog: ... These security fixes were backported from Apache 1.3.31: ... Updated package for Slackware 8.1: ...
      (Bugtraq)
    • [slackware-security] mc (SSA:2004-136-01)
      ... fix security issues that These could lead to a denial of service or the ... Sites that use mc should upgrade to the new mc package. ... Here are the details from the Slackware 9.1 ChangeLog: ... service or the execution of arbitrary code as the user running mc. ...
      (Bugtraq)
    • [slackware-security] lftp security update (SSA:2003-346-01)
      ... A security problem with lftp has been corrected with the release ... Here are the details from the Slackware 9.1 ChangeLog: ... this includes "security fixes in html ... WHERE TO FIND THE NEW PACKAGE: ...
      (Bugtraq)
    • TSLSA-2006-0024 - multi
      ... Trustix Secure Linux Security Advisory #2006-0024 ... Affected versions: Trustix Secure Linux 2.2 ... Package description: ... Mu Security has reported a vulnerability in Cyrus SASL ...
      (Bugtraq)