|
|
Log in / Subscribe / Register

kdelibs: certificate spoofing

Package(s): kdelibs CVE #(s): CVE-2011-3365 CVE-2011-3366
Created: October 11, 2011 Updated: November 10, 2011
Description: From the KDE advisory:

When displaying a security dialog with a certificate, KSSL does not properly force its QLabels to use QLabel::PlainText. As a result, if given a certificate containing rich text in its fields, it will render the rich text.

Specifically, a certificate containing a common name (CN) that has a table element will cause the second line of the table to be displayed. This can allow spoofing of the certificate's common name.

Alerts:
Gentoo 201412-09 racer-bin, fmod, PEAR-Mail, lvm2, gnucash, xine-lib, lastfmplayer, webkit-gtk, shadow, PEAR-PEAR, unixODBC, resource-agents, mrouted, rsync, xmlsec, xrdb, vino, oprofile, syslog-ng, sflowtool, gdm, libsoup, ca-certificates, gitolite, qt-creator 2014年12月11日
Gentoo 201406-34 kdelibs 2014年06月30日
CentOS CESA-2011:1385 kdelibs 2011年11月09日
Mandriva MDVSA-2011:162 kdelibs4 2011年11月01日
Ubuntu USN-1248-1 kde4libs 2011年10月25日
Scientific Linux SL-kdel-20111019 kdelibs and kdelibs3 2011年10月19日
CentOS CESA-2011:1385 kdelibs 2011年10月19日
Red Hat RHSA-2011:1385-01 kdelibs 2011年10月19日
openSUSE openSUSE-SU-2011:1135-1 kdelibs4 2011年10月17日
Scientific Linux SL-kdel-20111011 kdelibs 2011年10月11日
Red Hat RHSA-2011:1364-01 kdelibs 2011年10月11日

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds

AltStyle によって変換されたページ (->オリジナル) /