[ MDKSA-2007:157 ] - Updated kdelibs packages fix cross-site scripting (XSS) vulnerabilities
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDKSA-2007:157
http://www.mandriva.com/security/
_______________________________________________________________________
Package : kdelibs
Date : August 10, 2007
Affected: 2007.1
_______________________________________________________________________
Problem Description:
The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not
properly parse HTML comments, which allows remote attackers to conduct
cross-site scripting (XSS) attacks and bypass some XSS protection
schemes by embedding certain HTML tags within a comment in a title
tag, a related issue to CVE-2007-0478. Also affects kdelibs 3.5.6,
as per KDE official advisory.
Updated packages have been patched to prevent this.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0537
_______________________________________________________________________
Updated Packages:
Mandriva Linux 2007.1:
290249d063eb99aa0267060e28bd3d63
2007.1/i586/kdelibs-common-3.5.6-11.1mdv2007.1.i586.rpm
0392bf166e2b95b8274f67e24066dc8a
2007.1/i586/kdelibs-devel-doc-3.5.6-11.1mdv2007.1.i586.rpm
06107eb81ff8b184812f7a8ae31b52b9
2007.1/i586/libkdecore4-3.5.6-11.1mdv2007.1.i586.rpm
ffb71260989867bcec7d7fae45b86b5a
2007.1/i586/libkdecore4-devel-3.5.6-11.1mdv2007.1.i586.rpm
2f2938b43f88a2a197e6cc90b35c63b8
2007.1/SRPMS/kdelibs-3.5.6-11.1mdv2007.1.src.rpm
Mandriva Linux 2007.1/X86_64:
258cf38cce814a12a44c79c283de7c3d
2007.1/x86_64/kdelibs-common-3.5.6-11.1mdv2007.1.x86_64.rpm
70b9d63ac375ba65fb6c6b526dfe80f0
2007.1/x86_64/kdelibs-devel-doc-3.5.6-11.1mdv2007.1.x86_64.rpm
ee0681c70efd4cebb72a23b773d56f09
2007.1/x86_64/lib64kdecore4-3.5.6-11.1mdv2007.1.x86_64.rpm
664da181e64ab3f343b265cac6de0e87
2007.1/x86_64/lib64kdecore4-devel-3.5.6-11.1mdv2007.1.x86_64.rpm
2f2938b43f88a2a197e6cc90b35c63b8
2007.1/SRPMS/kdelibs-3.5.6-11.1mdv2007.1.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
iD8DBQFGvN99mqjQ0CJFipgRAkoiAJ9cYCEKSJXMFS0+C1kOsR82hamhUQCdHdlA
0d14cDmgZcJ1DxJi7dCNr3E=
=ix0J
-----END PGP SIGNATURE-----