First published: Tue Oct 11 2011(Updated: )
The kdelibs packages provide libraries for the K Desktop Environment (KDE).<br>An input sanitization flaw was found in the KSSL (KDE SSL Wrapper) API. An<br>attacker could supply a specially-crafted SSL certificate (for example, via<br>a web page) to an application using KSSL, such as the Konqueror web<br>browser, causing misleading information to be presented to the user,<br>possibly tricking them into accepting the certificate as valid.<br>(CVE-2011-3365)<br>This update also adds the following enhancement:<br><li> kdelibs provided its own set of trusted Certificate Authority (CA)</li> certificates. This update makes kdelibs use the system set from the<br>ca-certificates package, instead of its own copy. (BZ#743951)<br>Users should upgrade to these updated packages, which contain backported<br>patches to correct this issue and add this enhancement. The desktop must be<br>restarted (log out, then log back in) for this update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kdelibs | <4.3.4-11.el6_1.4 | 4.3.4-11.el6_1.4 |
redhat/kdelibs | <4.3.4-11.el6_1.4 | 4.3.4-11.el6_1.4 |
redhat/kdelibs-apidocs | <4.3.4-11.el6_1.4 | 4.3.4-11.el6_1.4 |
redhat/kdelibs-common | <4.3.4-11.el6_1.4 | 4.3.4-11.el6_1.4 |
redhat/kdelibs-debuginfo | <4.3.4-11.el6_1.4 | 4.3.4-11.el6_1.4 |
redhat/kdelibs-debuginfo | <4.3.4-11.el6_1.4 | 4.3.4-11.el6_1.4 |
redhat/kdelibs-devel | <4.3.4-11.el6_1.4 | 4.3.4-11.el6_1.4 |
redhat/kdelibs-devel | <4.3.4-11.el6_1.4 | 4.3.4-11.el6_1.4 |
redhat/kdelibs-common | <4.3.4-11.el6_1.4 | 4.3.4-11.el6_1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2011:1364 is classified as moderate.
RHSA-2011:1364 contains an input sanitization flaw in the KSSL API that can be exploited with specially-crafted SSL certificates.
To fix RHSA-2011:1364, upgrade the kdelibs packages to version 4.3.4-11.el6_1.4.
The affected packages in RHSA-2011:1364 include kdelibs, kdelibs-apidocs, kdelibs-common, and their respective debuginfo and devel packages.
There are no known workarounds for the vulnerability in RHSA-2011:1364; upgrading is recommended.