RHSA-2011:1385: Moderate: kdelibs and kdelibs3 security update
The kdelibs and kdelibs3 packages provide libraries for the K DesktopEnvironment (KDE).An input sanitization flaw was found in the KSSL (KDE SSL Wrapper) API. Anattacker could supply a specially-crafted SSL certificate (for example, viaa web page) to an application using KSSL, such as the Konqueror webbrowser, causing misleading information to be presented to the user,possibly tricking them into accepting the certificate as valid.(CVE-2011-3365)Users should upgrade to these updated packages, which contain a backportedpatch to correct this issue. The desktop must be restarted (log out, thenlog back in) for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2011:1385?
The severity of RHSA-2011:1385 is classified as moderate.
How do I fix RHSA-2011:1385?
To fix RHSA-2011:1385, you need to upgrade to kdelibs3 version 3.5.10-24.el6_1.1 or later.
Which packages are affected by RHSA-2011:1385?
The affected packages in RHSA-2011:1385 include kdelibs, kdelibs3, and their associated debug and development packages.
What vulnerability does RHSA-2011:1385 address?
RHSA-2011:1385 addresses an input sanitization flaw in the KSSL API that could allow an attacker to exploit applications using it.
Is there a workaround for RHSA-2011:1385?
There is no official workaround for RHSA-2011:1385; updating the affected packages is recommended.