[CLA-2004:843] Conectiva Security Announcement - kde

From: Conectiva Updates (secure_at_conectiva.com.br)
Date: 05/26/04

  • Next message: b0f www.b0f.net: "Re: [ GLSA 200405-18 ] Buffer Overflow in Firebird"
    Date: Wed, 26 May 2004 18:00:26 -0300
    To: conectiva-updates@papaleguas.conectiva.com.br, lwn@lwn.net, bugtraq@securityfocus.com, security-alerts@linuxsecurity.com, linsec@lists.seifried.org
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - --------------------------------------------------------------------------
    CONECTIVA LINUX SECURITY ANNOUNCEMENT
    - --------------------------------------------------------------------------

    PACKAGE : kde
    SUMMARY : Fix for URI handler vulnerability and other changes
    DATE : 2004-05-26 17:59:00
    ID : CLA-2004:843
    RELEVANT
    RELEASES : 8, 9

    - -------------------------------------------------------------------------

    DESCRIPTION
     KDE[1] is a very popular graphical desktop environment available for
     GNU/Linux and other operating systems.
     
     iDefense initially published[2] an advisory about a vulnerability[4]
     in the Opera browser. After some auditing, the KDE development team
     found out[3] that KDE has a similar vulnerability.
     
     The telnet, rlogin, ssh and mailto URI handlers in KDE do not check
     for '-' at the beginning of the hostname passed, which makes it
     possible to pass an option to the programs started by the handlers.
     
     KDE in Conetiva Linux 9, in addition to having these vulnerabilities
     fixed, is also being upgraded to the 3.1.5 version to address other
     problems not related to security.

    SOLUTION
     It is recommended that all users of the KDE desktop, including those
     who use other desktop and only use certain KDE components such as
     Konqueror or Kmail, upgrade their KDE packages.
     
     IMPORTANT: in order to close the vulnerbilities, all KDE applications
     have to be restarted.
     
     
     REFERENCES
     1. http://www.kde.org
     2. http://www.idefense.com/application/poi/display?id=104
     3. http://www.kde.org/info/security/advisory-20040517-1.txt
     4. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0411

    UPDATED PACKAGES
    ftp://atualizacoes.conectiva.com.br/8/SRPMS/kdelibs3-3.0.5b-1U80_3cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kdelibs-artsinterface-3.0.5b-1U80_3cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kdelibs-config-3.0.5b-1U80_3cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kdelibs-docbook-3.0.5b-1U80_3cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kdelibs3-3.0.5b-1U80_3cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kdelibs3-devel-3.0.5b-1U80_3cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/SRPMS/arts-1.1.5-26745U90_2cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/9/SRPMS/kdebase-3.1.5-28535U90_4cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/9/SRPMS/kdelibs3-3.1.5-28927U90_4cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/9/SRPMS/kdenetwork-3.1.5-29987U90_2cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/arts-1.1.5-26745U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/arts-common-libs-1.1.5-26745U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/arts-devel-1.1.5-26745U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/arts-devel-static-1.1.5-26745U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kde-common-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-common-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-core-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-devel-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-devel-static-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-doc-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kappfinder-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kate-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kcontrol-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kcontrol-doc-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kdesktop-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-khelpcenter-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-khelpcenter-doc-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kicker-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kicker-doc-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kio-smb-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kmenuedit-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kmenuedit-doc-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kscreensaver-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-ksysguard-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-ksysguard-doc-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-ktip-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kwin-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-kxkb-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-libkonq-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-nsplugins-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-sounds-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-themes-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdebase-wallpapers-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdelibs-artsinterface-3.1.5-28927U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdelibs-docbook-3.1.5-28927U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdelibs3-3.1.5-28927U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdelibs3-devel-3.1.5-28927U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-common-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-devel-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-doc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-kdict-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-kdict-doc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-kget-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-kit-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-kit-doc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-kmail-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-kmail-doc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-kmailcvt-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-knewsticker-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-knewsticker-doc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-knode-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-knode-doc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-korn-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-korn-doc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-krdc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-krfb-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-krfb-doc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-ksirc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-ksirc-doc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-ktalkd-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-ktalkd-doc-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-lanbrowsing-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdenetwork-sounds-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdm-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kdm-doc-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/konqueror-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/konqueror-doc-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/konsole-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/konsole-doc-3.1.5-28535U90_4cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kppp-3.1.5-29987U90_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kppp-doc-3.1.5-29987U90_2cl.i386.rpm

    ADDITIONAL INSTRUCTIONS
     The apt tool can be used to perform RPM packages upgrades:

     - run: apt-get update
     - after that, execute: apt-get upgrade

     Detailed instructions regarding the use of apt and upgrade examples
     can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en

    - -------------------------------------------------------------------------
    All packages are signed with Conectiva's GPG key. The key and instructions
    on how to import it can be found at
    http://distro.conectiva.com.br/seguranca/chave/?idioma=en
    Instructions on how to check the signatures of the RPM packages can be
    found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en

    - -------------------------------------------------------------------------
    All our advisories and generic update instructions can be viewed at
    http://distro.conectiva.com.br/atualizacoes/?idioma=en

    - -------------------------------------------------------------------------
    Copyright (c) 2004 Conectiva Inc.
    http://www.conectiva.com

    - -------------------------------------------------------------------------
    subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
    unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org

    iD8DBQFAtQVp42jd0JmAcZARAs/0AJ9FUqvBLIap6+QGlTgyycxu1w62NgCfTP+W
    hGoTcGb5Xs4czInQc1OXEBY=
    =Z8qw
    -----END PGP SIGNATURE-----


  • Next message: b0f www.b0f.net: "Re: [ GLSA 200405-18 ] Buffer Overflow in Firebird"

    Relevant Pages

    • [CLA-2003:668] Conectiva Security Announcement - kde
      ... PACKAGE: kde ... PS/PDF file handling vulnerability and other fixes ... Besides the fix for this vulnerability, the packages include other ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2003:569] Conectiva Linux Security Announcement - kde
      ... SUMMARY: Multiple vulnerabilities in KDE ... It is recommended that all KDE users upgrade their packages. ... ADDITIONAL INSTRUCTIONS ...
      (Bugtraq)
    • [CLA-2002:519] Conectiva Linux Security Announcement - kde
      ... X.509 certificate check vulnerability and other fixes ... This is a full update of the KDE desktop to the 3.0.3 version, ... It is recommended that all KDE users upgrade their packages. ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)
    • Re: HOWTO: Use KDE 3 from F8 on F10
      ... These packages are NO LONGER UPDATED. ... I can decide to take the risks. ... KDE app linked to the unpatched lib,... ... I will move to KDE4, ...
      (Fedora)
    • [CLA-2004:864] Conectiva Security Announcement - kde
      ... This announcement fixes the following vulnerabilities: ... account of any user which runs a KDE application. ... Konqueror, upgrade their KDE packages. ... Detailed instructions regarding the use of apt and upgrade examples ...
      (Bugtraq)