|
Message-ID: <4E89AB0B.2090200@kde.org>
Date: Mon, 03 Oct 2011 08:31:07 -0400
From: Jeff Mitchell <mitchell@....org>
To: oss-security@...ts.openwall.com,
Tim Brown <timb@...-dimension.org.uk>
Subject: KDE Security Advisory 20111003-1 published
Hello,
KDE Security Advisory 20111003-1 has been published and is available at
http://www.kde.org/info/security/advisory-20111003-1.txt.
This advisory concerns input validation failures affecting kdelibs and
Rekonq, due to using the default QLabel::AutoText behavior to display
externally-provided strings. This can be abused to show certificate
dialogs with spoofed Common Names (CNs), among other things.
The vulnerability and technical information about the exploit were
provided by Tim Brown of Nth Dimension. We thank them for their
responsible disclosure and cooperative handling of the matter.
The relevant CVEs are: CVE-2011-3365 KSSL and CVE-2011-3366 Rekonq
Thanks,
Jeff
Download attachment "signature.asc" of type "application/pgp-signature" (260 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.