Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Fedora Security Update Fixes kdelibs Address Bar Spoofing Weakness

Title : Fedora Security Update Fixes kdelibs Address Bar Spoofing Weakness
VUPEN ID : VUPEN/ADV-2007-3399
CVE ID : CVE-2007-3820 - CVE-2007-4224
Rated as : Low Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-10-09


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

Multiple vulnerabilities have been identified in Fedora, which could be exploited by malicious web sites to conduct spoofing or phishing attacks. These issues are caused by errors in kdelibs. For additional information, see : VUPEN/ADV-2007-2538 - VUPEN/ADV-2007-2807

Affected Products

Fedora Core 6

Solution

Upgrade the affected packages :

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/

34f81b9399ba4a07809cd6a029e10f9346c9dc07 SRPMS/kdelibs-3.5.7-1.fc6.src.rpm
34f81b9399ba4a07809cd6a029e10f9346c9dc07 noarch/kdelibs-3.5.7-1.fc6.src.rpm
7a9588bcdc92a218823a94e2db4e4692d09eeb93 ppc/kdelibs-apidocs-3.5.7-1.fc6.ppc.rpm
325e67bce67ed50f8b7b2c3c1f16940b4cf1aa44 ppc/kdelibs-devel-3.5.7-1.fc6.ppc.rpm
4a5c2d4bba45d7897d4417f629d3695f61510538 ppc/debug/kdelibs-debuginfo-3.5.7-1.fc6.ppc.rpm
97cdf1ce9fbceee9ebc90c7b2f1492861d4c1cef ppc/kdelibs-3.5.7-1.fc6.ppc.rpm
abaff9a1e79f988e96dec962e5a8c146a0f07ea0 x86_64/kdelibs-devel-3.5.7-1.fc6.x86_64.rpm
a5a6219f56cc0392d502485c3373237956caabd1 x86_64/kdelibs-3.5.7-1.fc6.x86_64.rpm
22d6c6be74b5ddbca61969ea69b3fa4b56534c23 x86_64/debug/kdelibs-debuginfo-3.5.7-1.fc6.x86_64.rpm
c3101b988f0fe1d16982089a2871652f62e29e5f x86_64/kdelibs-apidocs-3.5.7-1.fc6.x86_64.rpm
b96640aba59143a5c3fc4a48eb902482151a783b i386/debug/kdelibs-debuginfo-3.5.7-1.fc6.i386.rpm
75778c5783621ee62ba2954179a8eba73cf52bee i386/kdelibs-apidocs-3.5.7-1.fc6.i386.rpm
4c4a830290f66a1e518d8021ddd8dcb2ade5ef3b i386/kdelibs-devel-3.5.7-1.fc6.i386.rpm
928f18e52026752c4343584f89b298fd1ba5f675 i386/kdelibs-3.5.7-1.fc6.i386.rpm

References

http://www.vupen.com/english/advisories/2007/3399
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00085.html

ChangeLog

2007-10-09 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-07-06

     

  Microsoft Windows 0-Day
  Flaw Exploited in the Wild


  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy