Security Advisory kdebase security update

Advisory: RHSA-2003:146-07
Type: Security Advisory
Severity: Important
Issued on: 2003-05-22
Last updated on: 2003-06-19
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2003-0204

Details

This erratum provides updated KDE packages to resolve a vulnerability in
the handling of PostScript and PDF files.

KDE is a graphical desktop environment for the X Window System.

KDE versions up to and including KDE 3.1.1 have a vulnerability caused by
neglecting to use the -dSAFER option when previewing in Konquerer. An
attacker can prepare a malicious PostScript or PDF file which provides the
attacker with access to the victim's account and privileges when the victim
opens this malicious file for viewing, or when the victim browses a
directory containing this malicious file with file previews enabled in the
browser.

This erratum provides packages containing KDE 2.2.2 with backported patches
to correct these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
kdebase-2.2.2-9.src.rpm
File outdated by:  RHSA-2005:009
    19199c437e24c7b48d3f3ba8979e5e16
kdegraphics-2.2.2-4.src.rpm     643cf47e2ab269b403c9011e276e954c
kdelibs-2.2.2-7.src.rpm
File outdated by:  RHSA-2006:0720
    6e7c5689fe8939b3539f256ca2cff327
 
IA-32:
arts-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    0efd70c283c397b19f824d14ea1e0544
kdebase-2.2.2-9.i386.rpm
File outdated by:  RHSA-2005:009
    ce50008dfaf05ce58e63f3bb8084cf7e
kdebase-devel-2.2.2-9.i386.rpm
File outdated by:  RHSA-2005:009
    0097a70244485685e4bf10f633bdfb1f
kdegraphics-2.2.2-4.i386.rpm
File outdated by:  RHSA-2006:0648
    3f7e8f4532a387489db8d8740e4cec44
kdegraphics-devel-2.2.2-4.i386.rpm
File outdated by:  RHSA-2006:0648
    e75b62405389e9280a30e12005d37c8f
kdelibs-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    c8095d4755fe543e7745e15f328961fd
kdelibs-devel-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    a808a37c1be682d18399ad15228929e6
kdelibs-sound-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    d08876f5839d889446567621dd912645
kdelibs-sound-devel-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    f8e0c9fb60ead30c8c0d6f7bcbc6198a
 
IA-64:
arts-2.2.2-7.ia64.rpm
File outdated by:  RHSA-2006:0720
    06f19e4e648ba2b614b44d8322558486
kdebase-2.2.2-9.ia64.rpm
File outdated by:  RHSA-2005:009
    540afb4356a0a949b0b8fd304a4d1bf9
kdebase-devel-2.2.2-9.ia64.rpm
File outdated by:  RHSA-2005:009
    6ae14558370f9856f0c831ae3ac545c5
kdegraphics-2.2.2-4.ia64.rpm
File outdated by:  RHSA-2006:0648
    9ea228909d306427a24cfec44c38b5a8
kdegraphics-devel-2.2.2-4.ia64.rpm
File outdated by:  RHSA-2006:0648
    e4635d73674f4d3e03f5b1d36cb621a8
kdelibs-2.2.2-7.ia64.rpm
File outdated by:  RHSA-2006:0720
    d3f39f74b6e5f1e6419f4962cf52f7c1
kdelibs-devel-2.2.2-7.ia64.rpm
File outdated by:  RHSA-2006:0720
    968a52868f8052f6a0300e318034ecb0
kdelibs-sound-2.2.2-7.ia64.rpm
File outdated by:  RHSA-2006:0720
    de9f79038841dd626f81c9629e9f4ce0
kdelibs-sound-devel-2.2.2-7.ia64.rpm
File outdated by:  RHSA-2006:0720
    fc81ab1d9c71f367c77846dbd93ba45e
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
kdebase-2.2.2-9.src.rpm
File outdated by:  RHSA-2005:009
    19199c437e24c7b48d3f3ba8979e5e16
kdegraphics-2.2.2-4.src.rpm     643cf47e2ab269b403c9011e276e954c
kdelibs-2.2.2-7.src.rpm
File outdated by:  RHSA-2006:0720
    6e7c5689fe8939b3539f256ca2cff327
 
IA-32:
arts-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    0efd70c283c397b19f824d14ea1e0544
kdebase-2.2.2-9.i386.rpm
File outdated by:  RHSA-2005:009
    ce50008dfaf05ce58e63f3bb8084cf7e
kdebase-devel-2.2.2-9.i386.rpm
File outdated by:  RHSA-2005:009
    0097a70244485685e4bf10f633bdfb1f
kdegraphics-2.2.2-4.i386.rpm
File outdated by:  RHSA-2006:0648
    3f7e8f4532a387489db8d8740e4cec44
kdegraphics-devel-2.2.2-4.i386.rpm
File outdated by:  RHSA-2006:0648
    e75b62405389e9280a30e12005d37c8f
kdelibs-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    c8095d4755fe543e7745e15f328961fd
kdelibs-devel-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    a808a37c1be682d18399ad15228929e6
kdelibs-sound-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    d08876f5839d889446567621dd912645
kdelibs-sound-devel-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    f8e0c9fb60ead30c8c0d6f7bcbc6198a
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
kdebase-2.2.2-9.src.rpm
File outdated by:  RHSA-2005:009
    19199c437e24c7b48d3f3ba8979e5e16
kdegraphics-2.2.2-4.src.rpm     643cf47e2ab269b403c9011e276e954c
kdelibs-2.2.2-7.src.rpm
File outdated by:  RHSA-2006:0720
    6e7c5689fe8939b3539f256ca2cff327
 
IA-32:
arts-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    0efd70c283c397b19f824d14ea1e0544
kdebase-2.2.2-9.i386.rpm
File outdated by:  RHSA-2005:009
    ce50008dfaf05ce58e63f3bb8084cf7e
kdebase-devel-2.2.2-9.i386.rpm
File outdated by:  RHSA-2005:009
    0097a70244485685e4bf10f633bdfb1f
kdegraphics-2.2.2-4.i386.rpm
File outdated by:  RHSA-2006:0648
    3f7e8f4532a387489db8d8740e4cec44
kdegraphics-devel-2.2.2-4.i386.rpm
File outdated by:  RHSA-2006:0648
    e75b62405389e9280a30e12005d37c8f
kdelibs-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    c8095d4755fe543e7745e15f328961fd
kdelibs-devel-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    a808a37c1be682d18399ad15228929e6
kdelibs-sound-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    d08876f5839d889446567621dd912645
kdelibs-sound-devel-2.2.2-7.i386.rpm
File outdated by:  RHSA-2006:0720
    f8e0c9fb60ead30c8c0d6f7bcbc6198a
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
kdebase-2.2.2-9.src.rpm
File outdated by:  RHSA-2005:009
    19199c437e24c7b48d3f3ba8979e5e16
kdegraphics-2.2.2-4.src.rpm     643cf47e2ab269b403c9011e276e954c
kdelibs-2.2.2-7.src.rpm
File outdated by:  RHSA-2006:0720
    6e7c5689fe8939b3539f256ca2cff327
 
IA-64:
arts-2.2.2-7.ia64.rpm
File outdated by:  RHSA-2006:0720
    06f19e4e648ba2b614b44d8322558486
kdebase-2.2.2-9.ia64.rpm
File outdated by:  RHSA-2005:009
    540afb4356a0a949b0b8fd304a4d1bf9
kdebase-devel-2.2.2-9.ia64.rpm
File outdated by:  RHSA-2005:009
    6ae14558370f9856f0c831ae3ac545c5
kdegraphics-2.2.2-4.ia64.rpm
File outdated by:  RHSA-2006:0648
    9ea228909d306427a24cfec44c38b5a8
kdegraphics-devel-2.2.2-4.ia64.rpm
File outdated by:  RHSA-2006:0648
    e4635d73674f4d3e03f5b1d36cb621a8
kdelibs-2.2.2-7.ia64.rpm
File outdated by:  RHSA-2006:0720
    d3f39f74b6e5f1e6419f4962cf52f7c1
kdelibs-devel-2.2.2-7.ia64.rpm
File outdated by:  RHSA-2006:0720
    968a52868f8052f6a0300e318034ecb0
kdelibs-sound-2.2.2-7.ia64.rpm
File outdated by:  RHSA-2006:0720
    de9f79038841dd626f81c9629e9f4ce0
kdelibs-sound-devel-2.2.2-7.ia64.rpm
File outdated by:  RHSA-2006:0720
    fc81ab1d9c71f367c77846dbd93ba45e
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

88645 - Remove display of country flags from KDE
88798 - KDE PS/PDF file handling vulnerability


References


Keywords

KDE


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/