Security Advisory kdelibs security update

Advisory: RHSA-2003:193-08
Type: Security Advisory
Severity: Important
Issued on: 2003-06-17
Last updated on: 2003-06-17
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2003-0370

Details

Updated KDE packages that resolve a vulnerability in KDE's SSL
implementation are now available.

KDE is a graphical desktop environment for the X Window System.

KDE versions 2.2.2 and earlier have a vulnerability in their SSL
implementation that makes it possible for users of Konqueror and other SSL
enabled KDE software to fall victim to a man-in-the-middle attack.

Users of KDE should upgrade to these erratum packages, which contain KDE
2.2.2 with a backported patch to correct this vulnerability.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
kdelibs-2.2.2-8.src.rpm
File outdated by:  RHSA-2006:0720
    fb45ad45d2285fdd5ba12191ad28db67
 
IA-32:
arts-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    4416a5072f5a93b587daeffcee648a51
kdelibs-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    c1789b9b348d20b221cb06fa31865400
kdelibs-devel-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    b5b48bd629cb912bccf0752098563dc1
kdelibs-sound-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    55e69f4025b76734636c3496c5ff991c
kdelibs-sound-devel-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    4d12b124c017e6ab2aa3316fa0c78b10
 
IA-64:
arts-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2006:0720
    976b860e43a7410a3602f0ec200c459e
kdelibs-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2006:0720
    d5229b30587b5926ede2fb9eb8a2385e
kdelibs-devel-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2006:0720
    da92e135508e86a80470a28b8e7d6aaa
kdelibs-sound-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2006:0720
    bb1e8fd93e0b2cfef9d9f4310fe2efe7
kdelibs-sound-devel-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2006:0720
    aa39ae6d82f00847f82294df3c498e3f
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
kdelibs-2.2.2-8.src.rpm
File outdated by:  RHSA-2006:0720
    fb45ad45d2285fdd5ba12191ad28db67
 
IA-32:
arts-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    4416a5072f5a93b587daeffcee648a51
kdelibs-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    c1789b9b348d20b221cb06fa31865400
kdelibs-devel-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    b5b48bd629cb912bccf0752098563dc1
kdelibs-sound-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    55e69f4025b76734636c3496c5ff991c
kdelibs-sound-devel-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    4d12b124c017e6ab2aa3316fa0c78b10
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
kdelibs-2.2.2-8.src.rpm
File outdated by:  RHSA-2006:0720
    fb45ad45d2285fdd5ba12191ad28db67
 
IA-32:
arts-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    4416a5072f5a93b587daeffcee648a51
kdelibs-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    c1789b9b348d20b221cb06fa31865400
kdelibs-devel-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    b5b48bd629cb912bccf0752098563dc1
kdelibs-sound-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    55e69f4025b76734636c3496c5ff991c
kdelibs-sound-devel-2.2.2-8.i386.rpm
File outdated by:  RHSA-2006:0720
    4d12b124c017e6ab2aa3316fa0c78b10
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
kdelibs-2.2.2-8.src.rpm
File outdated by:  RHSA-2006:0720
    fb45ad45d2285fdd5ba12191ad28db67
 
IA-64:
arts-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2006:0720
    976b860e43a7410a3602f0ec200c459e
kdelibs-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2006:0720
    d5229b30587b5926ede2fb9eb8a2385e
kdelibs-devel-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2006:0720
    da92e135508e86a80470a28b8e7d6aaa
kdelibs-sound-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2006:0720
    bb1e8fd93e0b2cfef9d9f4310fe2efe7
kdelibs-sound-devel-2.2.2-8.ia64.rpm
File outdated by:  RHSA-2006:0720
    aa39ae6d82f00847f82294df3c498e3f
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

92144 - CVE-NO-MATCH KDE SSL CA checking implementation vulnerability


References


Keywords

IP, malicious, spoofing


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/