CVE-2011-3365: Input Validation

Published Oct 3, 2011
·
Updated

An input validation failure was discovered in KSSL (CVE-2011-3365) and Rekonq (CVE-2011-3366) in KDE SC 4.6.0 up to and including KDE SC 4.7.1, however upstream indicates that ealier versions of KDE SC may also be affected. The upstream advisory [1] details are noted below:

The default rendering type for a QLabel is QLabel::AutoText, which uses heuristics to determine whether to render the given content as plain text or rich text.

When displaying a security dialog with a certificate, KSSL does not properly force its QLabels to use QLabel::PlainText. As a result, if given a certificate containing rich text in its fields, it will render the rich text.

Specifically, a certificate containing a common name (CN) that has a table element will cause the second line of the table to be displayed. This can allow spoofing of the certificate's common name.

The vulnerability and technical information about the exploit were provided by Tim Brown of Nth Dimension. We thank them for their responsible disclosure and cooperative handling of the matter.

Exploitation may trick the user into beliving a certificate is legitimate when in fact it is invalid, and simply displayed incorrectly.

This has been corrected via the following git [2] commits:

4.6 branch: 9ca2b26f 90607b28 4.7 branch: bd70d4e5 86622e4d frameworks: bd70d4e5 86622e4d

(Note: the second commit for each branch above is a fix for kiohttp that fixes a similar issue, but with only very minor security implications.)

And for Rekonq, the following commits correct it in git [3]:

85f454fa 526ce56f d1711fff

Finally, Qt has also received a patch to warn users about sanitizing their QLabel [4].

[1] http://www.kde.org/info/security/advisory-20111003-1.txt [2] http://quickgit.kde.org/?p=kdelibs.git&a=summary [3] http://quickgit.kde.org/?p=rekonq.git&a=summary [4] https://qt.gitorious.org/qt/qt/commit/31f7ecbdcdbafbac5bbfa693e4d060757244941b

Other sources

The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

Affected Software

12 affected componentsFixes available
redhat/kdelibs<6:3.3.1-18.el4
6:3.3.1-18.el4
redhat/kdelibs<6:3.5.4-26.el5_7.1
6:3.5.4-26.el5_7.1
redhat/kdelibs<6:4.3.4-11.el6_1.4
6:4.3.4-11.el6_1.4
redhat/kdelibs3<0:3.5.10-24.el6_1.1
0:3.5.10-24.el6_1.1
KDE KDE SC=4.6.0
KDE KDE SC=4.6.1
KDE KDE SC=4.6.2
KDE KDE SC=4.6.3
KDE KDE SC=4.6.4
KDE KDE SC=4.6.5
KDE KDE SC=4.7.0
KDE KDE SC=4.7.1

Event History

Oct 3, 2011
CVE Published
12:00 AM
Data Sourced
05:45 PM
DescriptionSeverityAffected Software
Nov 29, 2011
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2011-3365?

CVE-2011-3365 is rated as a moderate severity vulnerability due to an input validation failure.

2

How do I fix CVE-2011-3365?

To fix CVE-2011-3365, upgrade to a version of kdelibs that is later than 6:3.3.1-18.el4 or the appropriate patched version for your distribution.

3

Which versions are affected by CVE-2011-3365?

CVE-2011-3365 affects KDE SC versions from 4.6.0 up to and including 4.7.1.

4

What software does CVE-2011-3365 impact?

CVE-2011-3365 impacts the kdelibs package in various versions and distributions of KDE SC.

5

Is there a patch available for CVE-2011-3365?

Yes, patches for CVE-2011-3365 are available as part of updates to affected kdelibs versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203