Home | Docs | Forums | Lists | Bugs | Planet | Store | GMN | Get Gentoo!
Not eligible to see or edit group visibility for this bug.
View Bug Activity | Format For Printing | XML | Clone This Bug
KDE Security Advisory: langen2kvtml tempfile vulnerability Original Release Date: 2008-08-15 URL: http://www.kde.org/info/security/advisory-20050815-1.txt 0. References 1. Systems affected: All KDE releases starting from KDE 3.0 up to including KDE 3.4.2. 2. Overview: Ben Burton notified the KDE security team about several tempfile handling related vulnerabilities in langen2kvtml, a conversion script for kvoctrain. The script must be manually invoked. The script uses known filenames in /tmp which allow an local attacker to overwrite files writeable by the user invoking the conversion script. 3. Impact: A local file can overwrite files and possibly elevate privileges. 4. Solution: Source code patches have been made available which fix these vulnerabilities. Contact your OS vendor / binary package provider for information about how to obtain updated binary packages. 5. Patch: Patch for KDE 3.4.2 is available from ftp://ftp.kde.org/pub/kde/security_patches : XXX Patch for KDE 3.3.1 is available from ftp://ftp.kde.org/pub/kde/security_patches : 651fba579516ea947fbefee373f40a6c post-3.3.1-kdegraphics.diff
Created an attachment (id=65692) [edit] post-3.4.2-kdeedu.diff Proposed upstream patch.
RH seems to have accidentially put out updated kdeedu packages (though I haven't actually found it yet). If correct this is SEMIPUBLIC instead of CONFIDENTIAL.
Fedora updates here: http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/i386/kdeedu-3.4.2-0.fc4.2.i386.rpm
<<< kdeedu-3.3.2-r2.ebuild <<< kdeedu-3.4.1-r1.ebuild <<< kvoctrain-3.4.1-r1.ebuild are marked x86, the other archs are asked to follow.
Well, i don't have a good feeling that these patches are in portage but since it's semi-public, i just hope that it's ok. Would be too late now, anyways. Arches, please test and mark kdeedu-3.3.2-r2 stable. if kde-3.4.1 was stable on your arch, please do the same with kdeedu-3.4.1-r1 and kvoctrain-3.4.1-r1. Thanks a lot.
Removing arches and adding arch security liaisons instead. Please test and mark stable.
This is now handled on the public bug #102577
removing as it is stable on ppc64
Stable on ppc.
x86 already there
Closing, as we are done here. *** This bug has been marked as a duplicate of 102577 ***