oss-sec mailing list archives

CVE Request -- kdebase4 (konqueror) -- Incomplete SSL Certificate support in KDE4


From: Jan Lieskovsky <jlieskov () redhat com>
Date: Tue, 12 May 2009 16:00:46 +0200

Hello Steve,

  not sure if original Debian bug [1] reporter meant this insufficiency,
but [2] might be interesting for your attention. While this is not
direct security vulnerability, is is preventing users from using
the functionality provided by digital certificates.

References:
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526979
[2] https://bugs.kde.org/show_bug.cgi?id=185288
[3] https://bugzilla.redhat.com/show_bug.cgi?id=500373

This issue is present only in Konqueror web browser, as shipped
with the K Desktop Environment 4 (kdebase-4.*). Konqueror in
kdebase3 works fine.

Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team


Current thread: