Date: Mon, 03 Oct 2011 08:31:07 -0400 From: Jeff Mitchell <mitchell@....org> To: oss-security@...ts.openwall.com, Tim Brown <timb@...-dimension.org.uk> Subject: KDE Security Advisory 20111003-1 published Hello, KDE Security Advisory 20111003-1 has been published and is available at http://www.kde.org/info/security/advisory-20111003-1.txt. This advisory concerns input validation failures affecting kdelibs and Rekonq, due to using the default QLabel::AutoText behavior to display externally-provided strings. This can be abused to show certificate dialogs with spoofed Common Names (CNs), among other things. The vulnerability and technical information about the exploit were provided by Tim Brown of Nth Dimension. We thank them for their responsible disclosure and cooperative handling of the matter. The relevant CVEs are: CVE-2011-3365 KSSL and CVE-2011-3366 Rekonq Thanks, Jeff Download attachment "signature.asc" of type "application/pgp-signature" (260 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.