New User, Welcome!     Login

KDE 4

Secunia Research: KDE Okular PDB Parsing RLE Decompression Buffer Overflow

Where:  Remote

====================================================================== 
3) Vendor's Description of Software 

"Okular is a universal document viewer based on KPDF for KDE 4.".

Product Link:
http://okular.kde.org/

====================================================================== 

[SECURITY] [DSA 1868-1] New kde4libs packages fix several vulnerabilities

Debian Security Advisory DSA-1868-1                  security@debian.org
http://www.debian.org/security/                      Steffen Joeris
August 19, 2009                       http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package        : kde4libs                             
Vulnerability  : several vulnerabilities              
Problem type   : local (remote)                       
Debian-specific: no
CVE Ids        : CVE-2009-1690 CVE-2009-1698 CVE-2009-1687
Debian Bugs    : 534949

[USN-871-2] KDE 4 vulnerabilities

===========================================================
Ubuntu Security Notice USN-871-2          December 11, 2009
kde4libs vulnerabilities
https://launchpad.net/bugs/495301
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.10
Ubuntu 9.04

[USN-1110-1] KDE-Libs vulnerabilities

==========================================================================
Ubuntu Security Notice USN-1110-1
April 14, 2011

kde4libs vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.10

[USN-1114-1] KDENetwork vulnerability

An attacker could overwrite files owned by the user if KGet opened a
crafted metalink file.

Software Description:
- kdenetwork: networking applications for KDE 4

Details:

It was discovered that KGet did not properly perform input validation when
processing metalink files. If a user were tricked into opening a crafted



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!