Security Alert for KDE users

Puppy related raves and general interest that doesn't fit anywhere else
Post Reply
Message
Author
Guest

Security Alert for KDE users

#1 Post by Guest »

KDE flaws put Linux, Unix systems at risk
By Joris Evers
Staff Writer, CNET News.com
Published: January 20, 2006, 11:44 AM PST

A serious vulnerability has been found in the popular KDE open-source software bundle. The flaw, deemed "critical" by the research outfit the French Security Incident Response Team, could allow a remote attacker to gain control over vulnerable systems. KDE is a desktop software package for Linux and Unix systems and includes the Konqueror Web browser and other applications.

The vulnerability lies in the JavaScript interpreter engine used by Konqueror and other parts of KDE, according to a security advisory posted Thursday. An attacker could craft a special UTF-8 encoded URI sequence to exploit the flaw, according to the advisory. For an attack to be successful, a person would have to visit the attacker's Web page using Konqueror, the FrSIRT said in its alert. Affected are KDE 3.2.0 up to and including KDE 3.5.0. Fixes are available.
Source

and it begins :cry: just because Linux wasn't that widely used I think not too many vulnerabilities were exploited but it seems that is about to change.
I hope am wrong.

btw ,did you guys know about this:
http://secunia.com/advisories/14295/

good site to chk on stuff like that;
http://www.insecure.org/sploits_linux.html
http://www.linuxsecurity.com/advisories/


can we have a section for security updates and alerts?
did i mention that I'm paranoid :lol:
Last edited by Guest on Sun 22 Jan 2006, 08:49, edited 1 time in total.

User avatar
babbs
Posts: 397
Joined: Tue 10 May 2005, 06:35
Location: Tijuana, BCN, Mexico

#2 Post by babbs »

Dingo,

I make it a point to visit http://www.ghostship.com/ on a daily basis. If you've never been there, its worth a visit. (The site is INFOSYSSEC, The Security Portal for Information System Security Professionals.)

Babbs

muskrat
Posts: 24
Joined: Sun 03 Jul 2005, 17:46
Location: Gulf Coast TX-MX
Contact:

#3 Post by muskrat »

Konqueror has had security issues for some time now, they fix them and it seems they come back. For that reason I don't use Konqueror as a web browser, just use it for local file manager.

In this case I think in all probality this explote is aimed at Java more than Linux, I would imagine IE in that other infamous OS is also a target! It just happen Konqueror gets caught up in it.
Steve (Muskrat) McMullen
http://www.muskratsweb.com
Registered Linux User #305785

Post Reply