[Frugalware-security] [ FSA-280 ] kdebase
vmiklos
noreply at frugalware.org
Mon Sep 24 12:10:37 CEST 2007
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Frugalware Security Advisory FSA-280
Date: 2007-09-24
Package: kdebase
Vulnerable versions: <= 3.5.6-3terminus1
Unaffected versions: >= 3.5.6-3terminus2
Related bugreport: http://bugs.frugalware.org/task/2430
CVE: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4569
Description
===========
KDE has acknowledged a security issue in KDM, which can be exploited by malicious, local users to bypass certain security restrictions.
The security issue is caused due to an error when checking the credentials during login, which can be exploited to log in to an account (potentially including "root") without specifying a valid password.
Updated Packages
================
Check if you have kdebase installed:
# pacman-g2 -Q kdebase
If found, then you should upgrade to the latest version:
# pacman-g2 -Sy kdebase
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: See http://ftp.frugalware.org/pub/README.GPG for info
iD8DBQFG940dZ7NElSD1VhkRAiNMAJ4lZnzVok24gtqtki1GlKmv63kNnwCeOhXf
7XLx7Mq/YvszmZPQCxRK5n8=
=5I2G
-----END PGP SIGNATURE-----
More information about the Frugalware-security
mailing list