oss-sec mailing list archives

KDE Security Advisory 20111003-1 published


From: Jeff Mitchell <mitchell () kde org>
Date: Mon, 03 Oct 2011 08:31:07 -0400

Hello,

KDE Security Advisory 20111003-1 has been published and is available at
http://www.kde.org/info/security/advisory-20111003-1.txt.

This advisory concerns input validation failures affecting kdelibs and
Rekonq, due to using the default QLabel::AutoText behavior to display
externally-provided strings. This can be abused to show certificate
dialogs with spoofed Common Names (CNs), among other things.

The vulnerability and technical information about the exploit were
provided by Tim Brown of Nth Dimension. We thank them for their
responsible disclosure and cooperative handling of the matter.

The relevant CVEs are: CVE-2011-3365 KSSL and CVE-2011-3366 Rekonq

Thanks,
Jeff

Attachment: signature.asc
Description: OpenPGP digital signature


Current thread: