CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:S/C:C/I:C/A:C
EPSS
Percentile
89.4%
CentOS Errata and Security Advisory CESA-2007:0905
The kdebase packages provide the core applications for KDE, the K Desktop
Environment. These core packages include Konqueror, the web browser and
file manager.
These updated packages address the following vulnerabilities:
Kees Huijgen found a flaw in the way KDM handled logins when autologin and
“shutdown with password” were enabled. A local user would have been able
to login via KDM as any user without requiring a password. (CVE-2007-4569)
Two Konqueror address spoofing flaws were discovered. A malicious web site
could spoof the Konqueror address bar, tricking a victim into believing the
page was from a different site. (CVE-2007-3820, CVE-2007-4224)
Users of KDE should upgrade to these updated packages, which contain
backported patches to correct these issues.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2007-October/076447.html
https://lists.centos.org/pipermail/centos-announce/2007-October/076449.html
https://lists.centos.org/pipermail/centos-announce/2007-October/076456.html
https://lists.centos.org/pipermail/centos-announce/2007-October/076457.html
https://lists.centos.org/pipermail/centos-announce/2007-October/076460.html
https://lists.centos.org/pipermail/centos-announce/2007-October/076461.html
Affected packages:
kdebase
kdebase-devel
Upstream details at:
https://access.redhat.com/errata/RHSA-2007:0905
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 4 | ia64 | kdebase | < 3.3.1-6.el4 | kdebase-3.3.1-6.el4.ia64.rpm |
CentOS | 4 | ia64 | kdebase-devel | < 3.3.1-6.el4 | kdebase-devel-3.3.1-6.el4.ia64.rpm |
CentOS | 4 | s390 | kdebase | < 3.3.1-6.el4 | kdebase-3.3.1-6.el4.s390.rpm |
CentOS | 4 | s390 | kdebase-devel | < 3.3.1-6.el4 | kdebase-devel-3.3.1-6.el4.s390.rpm |
CentOS | 4 | s390x | kdebase | < 3.3.1-6.el4 | kdebase-3.3.1-6.el4.s390x.rpm |
CentOS | 4 | s390x | kdebase-devel | < 3.3.1-6.el4 | kdebase-devel-3.3.1-6.el4.s390x.rpm |
CentOS | 4 | i386 | kdebase | < 3.3.1-6.el4 | kdebase-3.3.1-6.el4.i386.rpm |
CentOS | 4 | x86_64 | kdebase | < 3.3.1-6.el4 | kdebase-3.3.1-6.el4.x86_64.rpm |
CentOS | 4 | x86_64 | kdebase-devel | < 3.3.1-6.el4 | kdebase-devel-3.3.1-6.el4.x86_64.rpm |
CentOS | 4 | i386 | kdebase | < 3.3.1-6.el4 | kdebase-3.3.1-6.el4.i386.rpm |