From 9da119a4e74d459e7cedfeb916add2ebe3227f2a Mon Sep 17 00:00:00 2001 From: Jacques Vidrine Date: Thu, 12 Aug 2004 21:07:06 +0000 Subject: Add two issues covering three KDE advisories: two temporary file handling issues, and a KHTML issue. --- security/vuxml/vuln.xml | 67 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) (limited to 'security/vuxml/vuln.xml') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index cebf1644f307..60260b144609 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,73 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> + + KDE Konqueror frame injection vulnerability + + + kdelibs + 3.2.3_3 + + + kdebase + 3.2.3_1 + + + + +

A KDE Security Advisory reports:

+
+

A malicious website could abuse Konqueror to insert + its own frames into the page of an otherwise trusted + website. As a result the user may unknowingly send + confidential information intended for the trusted website + to the malicious website.

+
+ +
+ + CAN-2004-0721 + http://secunia.com/advisories/11978/ + ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-htmlframes.patch + ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdebase-htmlframes.patch + + + 2004-08-11 + 2004-08-12 + +
+ + + kdelibs insecure temporary file handling + + + kdelibs + 3.2.3_3 + + + + +

According to a KDE Security Advisory, KDE may sometimes + create temporary files without properly checking the ownership + and type of the target path. This could allow a local + attacker to cause KDE applications to overwrite arbitrary + files.

+ +
+ + CAN-2004-0689 + CAN-2004-0690 + http://www.kde.org/info/security/advisory-20040811-1.txt + http://www.kde.org/info/security/advisory-20040811-2.txt + ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-kstandarddirs.patch + ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-dcopserver.patch + + + 2004-08-11 + 2004-08-12 + +
+ gaim remotely exploitable vulnerabilities in MSN component -- cgit v1.2.3