--===============1067495574== Content-Type: multipart/signed; boundary="nextPart2328435.71HhMPtzjW"; protocol="application/pgp-signature"; micalg=pgp-sha1 Content-Transfer-Encoding: 7bit --nextPart2328435.71HhMPtzjW Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline KDE Security Advisory: langen2kvtml tempfile vulnerability Original Release Date: 2008-08-15 URL: http://www.kde.org/info/security/advisory-20050815-1.txt 0. References CAN-2005-2101 1. Systems affected: All KDE releases starting from KDE 3.0 up to including KDE 3.4.2. 2. Overview: Ben Burton notified the KDE security team about several tempfile handling related vulnerabilities in langen2kvtml, a conversion script for kvoctrain. This vulnerability was initially discovered by Javier Fern=E1ndez-Sanguino Pe=F1a. The script uses known filenames in /tmp which allow an local attacker to overwrite files writeable by the user (manually) invoking the conversion script. 3. Impact: A local file can overwrite files and possibly elevate privileges. 4. Solution: Source code patches have been made available which fix these vulnerabilities. Contact your OS vendor / binary package provider for information about how to obtain updated binary packages. 5. Patch: Patch for KDE 3.4.2 is available from=20 ftp://ftp.kde.org/pub/kde/security_patches : 0e82c5810df3b04370188ba13cc50203 post-3.4.2-kdeedu.diff --nextPart2328435.71HhMPtzjW Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) iD8DBQBC/+sUvsXr+iuy1UoRAp2VAJ9UI1ABzUP24uP8YmxCAH2dzqGc4wCg8BSt AM5zlZW0C9/QysAUgmpkFK8= =e+8l -----END PGP SIGNATURE----- --nextPart2328435.71HhMPtzjW-- --===============1067495574== Content-Type: text/plain; charset="iso-8859-1" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline _______________________________________________ kde-announce mailing list kde-announce@kde.org https://mail.kde.org/mailman/listinfo/kde-announce --===============1067495574==--