Skip to navigation

Security Advisory Updated KDE packages fix security issue

Advisory: RHSA-2003:192-07
Type: Security Advisory
Severity: N/A
Issued on: 2003-06-05
Last updated on: 2003-06-05
Affected Products: Red Hat Linux 7.1
Red Hat Linux 7.2
CVEs (cve.mitre.org): CVE-2003-0370

Details

Updated KDE packages that resolve a vulnerability in KDE's SSL
implementation are now available.

KDE is a graphical desktop environment for the X Window System.

KDE versions 2.2.2 and earlier have a vulnerability in their SSL
implementation that makes it possible for users of Konqueror and other SSL
enabled KDE software to fall victim to a man-in-the-middle attack. Red Hat
Linux 7.1 and 7.2 shipped with KDE packages that are vulnerable to this issue.

Users of KDE should upgrade to these erratum packages, which contain KDE
2.2.2 with a backported patch to correct this vulnerability.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 7.1

IA-32:
arts-2.2.2-0.71.3.i386.rpm
File outdated by:  RHSA-2003:235
    MD5: 3cf838774dd099fd2e2611aa109afd7e
kdelibs-2.2.2-0.71.3.i386.rpm
File outdated by:  RHSA-2003:235
    MD5: b7a877bd55c56861d075571bf257ff04
kdelibs-devel-2.2.2-0.71.3.i386.rpm
File outdated by:  RHSA-2003:235
    MD5: a55f18bd1341220e5c8f8e8752fe5195
kdelibs-sound-2.2.2-0.71.3.i386.rpm
File outdated by:  RHSA-2003:235
    MD5: 7c5d3cbc427c14e60bedd0d5f06277d5
kdelibs-sound-devel-2.2.2-0.71.3.i386.rpm
File outdated by:  RHSA-2003:235
    MD5: 7da55a0cfa8d18c2d7d0ec8cf4a2bf48
 
Red Hat Linux 7.2

SRPMS:
kdelibs-2.2.2-8.src.rpm
File outdated by:  RHSA-2003:235
    MD5: fb45ad45d2285fdd5ba12191ad28db67
 
IA-32:
arts-2.2.2-8.i386.rpm
File outdated by:  RHSA-2003:235
    MD5: 4416a5072f5a93b587daeffcee648a51
kdelibs-2.2.2-8.i386.rpm
File outdated by:  RHSA-2003:235
    MD5: c1789b9b348d20b221cb06fa31865400
kdelibs-devel-2.2.2-8.i386.rpm
File outdated by:  RHSA-2003:235
    MD5: b5b48bd629cb912bccf0752098563dc1
kdelibs-sound-2.2.2-8.i386.rpm
File outdated by:  RHSA-2003:235
    MD5: 55e69f4025b76734636c3496c5ff991c
kdelibs-sound-devel-2.2.2-8.i386.rpm
File outdated by:  RHSA-2003:235
    MD5: 4d12b124c017e6ab2aa3316fa0c78b10
 
IA-64:
arts-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2003:235
    MD5: 976b860e43a7410a3602f0ec200c459e
kdelibs-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2003:235
    MD5: d5229b30587b5926ede2fb9eb8a2385e
kdelibs-devel-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2003:235
    MD5: da92e135508e86a80470a28b8e7d6aaa
kdelibs-sound-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2003:235
    MD5: bb1e8fd93e0b2cfef9d9f4310fe2efe7
kdelibs-sound-devel-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2003:235
    MD5: aa39ae6d82f00847f82294df3c498e3f
 

References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/