The kdebase packages provide the core applications for KDE, the K Desktop
Environment. These core packages include Konqueror, the web browser and
file manager.
These updated packages address the following vulnerabilities:
Kees Huijgen found a flaw in the way KDM handled logins when autologin and
“shutdown with password” were enabled. A local user would have been able
to login via KDM as any user without requiring a password. (CVE-2007-4569)
Two Konqueror address spoofing flaws were discovered. A malicious web site
could spoof the Konqueror address bar, tricking a victim into believing the
page was from a different site. (CVE-2007-3820, CVE-2007-4224)
Users of KDE should upgrade to these updated packages, which contain
backported patches to correct these issues.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | 4 | x86_64 | kdebase | < 3.3.1-6.el4 | kdebase-3.3.1-6.el4.x86_64.rpm |
RedHat | 5 | x86_64 | kdebase-devel | < 3.5.4-15.el5 | kdebase-devel-3.5.4-15.el5.x86_64.rpm |
RedHat | 4 | src | kdebase | < 3.3.1-6.el4 | kdebase-3.3.1-6.el4.src.rpm |
RedHat | 5 | src | kdebase | < 3.5.4-15.el5 | kdebase-3.5.4-15.el5.src.rpm |
RedHat | 5 | s390 | kdebase | < 3.5.4-15.el5 | kdebase-3.5.4-15.el5.s390.rpm |
RedHat | 5 | i386 | kdebase | < 3.5.4-15.el5 | kdebase-3.5.4-15.el5.i386.rpm |
RedHat | 5 | ia64 | kdebase | < 3.5.4-15.el5 | kdebase-3.5.4-15.el5.ia64.rpm |
RedHat | 5 | x86_64 | kdebase | < 3.5.4-15.el5 | kdebase-3.5.4-15.el5.x86_64.rpm |
RedHat | 4 | s390 | kdebase-devel | < 3.3.1-6.el4 | kdebase-devel-3.3.1-6.el4.s390.rpm |
RedHat | 4 | x86_64 | kdebase-devel | < 3.3.1-6.el4 | kdebase-devel-3.3.1-6.el4.x86_64.rpm |