[Frugalware-security] [ FSA-280 ] kdebase

vmiklos noreply at frugalware.org
Mon Sep 24 12:10:37 CEST 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Frugalware Security Advisory                           FSA-280

Date: 2007-09-24
Package: kdebase
Vulnerable versions: <= 3.5.6-3terminus1
Unaffected versions: >= 3.5.6-3terminus2
Related bugreport: http://bugs.frugalware.org/task/2430
CVE: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4569

Description
===========

KDE has acknowledged a security issue in KDM, which can be exploited by malicious, local users to bypass certain security restrictions.
The security issue is caused due to an error when checking the credentials during login, which can be exploited to log in to an account (potentially including &quot;root&quot;) without specifying a valid password.

Updated Packages
================

Check if you have kdebase installed:

	# pacman-g2 -Q kdebase

If found, then you should upgrade to the latest version:

	# pacman-g2 -Sy kdebase

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: See http://ftp.frugalware.org/pub/README.GPG for info

iD8DBQFG940dZ7NElSD1VhkRAiNMAJ4lZnzVok24gtqtki1GlKmv63kNnwCeOhXf
7XLx7Mq/YvszmZPQCxRK5n8=
=5I2G
-----END PGP SIGNATURE-----


More information about the Frugalware-security mailing list