Package(s): kdelibs
CVE #(s): CVE-2011-3365
CVE-2011-3366
Created: October 11, 2011
Updated: November 10, 2011
Description:
From the KDE advisory:
When displaying a security dialog with a certificate, KSSL does not properly force its QLabels to use QLabel::PlainText. As a result, if given a certificate containing rich text in its fields, it will render the rich text.
Specifically, a certificate containing a common name (CN) that has a table element will cause the second line of the table to be displayed. This can allow spoofing of the certificate's common name.
Alerts:
Gentoo
201412-09
racer-bin, fmod, PEAR-Mail, lvm2, gnucash, xine-lib, lastfmplayer, webkit-gtk, shadow, PEAR-PEAR, unixODBC, resource-agents, mrouted, rsync, xmlsec, xrdb, vino, oprofile, syslog-ng, sflowtool, gdm, libsoup, ca-certificates, gitolite, qt-creator
2014年12月11日
Gentoo
201406-34
kdelibs
2014年06月30日
CentOS
CESA-2011:1385
kdelibs
2011年11月09日
Mandriva
MDVSA-2011:162
kdelibs4
2011年11月01日
Ubuntu
USN-1248-1
kde4libs
2011年10月25日
Scientific Linux
SL-kdel-20111019
kdelibs and kdelibs3
2011年10月19日
CentOS
CESA-2011:1385
kdelibs
2011年10月19日
Red Hat
RHSA-2011:1385-01
kdelibs
2011年10月19日
openSUSE
openSUSE-SU-2011:1135-1
kdelibs4
2011年10月17日
Scientific Linux
SL-kdel-20111011
kdelibs
2011年10月11日
Red Hat
RHSA-2011:1364-01
kdelibs
2011年10月11日