Summary: | kde-base/kdebase: Konqueror Cross-Domain Cookie Injection Vulnerability | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Florian Schilhabel (RETIRED) <ruth> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | kde |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.kde.org/info/security/advisory-20040823-1.txt | ||
Whiteboard: | A4 [glsa] jaervosz | ||
Package list: | Runtime testing required: | --- |
Description
Florian Schilhabel (RETIRED)
![]() kde please provide an updated ebuild. it's already been integrated in the kdelibs-3.2.3-r1 ebuild for some time now. caleb are you sure? It's a new one for kcookiejar and timestamp on the ftp server is from yesterday evening. ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-kcookiejar.patch lovely - they released the patch to me some time ago and then changed it before they put it in the wild without notifying of the update. anyway, kdelibs-3.2.3-r2.ebuild uses this new overwritten patch. thank you, __that__ was fast... ;) so long florian seems stable keywords were carried over... so the new ebuild is already stable on amd64. these keywords are already stable. Caleb thx for the swift reaction. This is ready for GLSA. Security please draft. GLSA 200408-23. |