Oracle Linux 4 / 5 : kdebase (ELSA-2007-0905)

medium Nessus Plugin ID 67573

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

From Red Hat Security Advisory 2007:0905 :

Updated kdebase packages that resolve several security flaws are now available for Red Hat Enterprise Linux 4 and 5.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

The kdebase packages provide the core applications for KDE, the K Desktop Environment. These core packages include Konqueror, the web browser and file manager.

These updated packages address the following vulnerabilities :

Kees Huijgen found a flaw in the way KDM handled logins when autologin and 'shutdown with password' were enabled. A local user would have been able to login via KDM as any user without requiring a password.
(CVE-2007-4569)

Two Konqueror address spoofing flaws were discovered. A malicious website could spoof the Konqueror address bar, tricking a victim into believing the page was from a different site. (CVE-2007-3820, CVE-2007-4224)

Users of KDE should upgrade to these updated packages, which contain backported patches to correct these issues.

Solution

Update the affected kdebase packages.

See Also

https://oss.oracle.com/pipermail/el-errata/2007-October/000355.html

https://oss.oracle.com/pipermail/el-errata/2007-October/000358.html

Plugin Details

Severity: Medium

ID: 67573

File Name: oraclelinux_ELSA-2007-0905.nasl

Version: 1.16

Type: local

Agent: unix

Published: 7/12/2013

Updated: 1/14/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:oracle:linux:kdebase, p-cpe:/a:oracle:linux:kdebase-devel, cpe:/o:oracle:linux:4, cpe:/o:oracle:linux:5

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/OracleLinux

Exploit Ease: No known exploits are available

Patch Publication Date: 10/8/2007

Vulnerability Publication Date: 7/16/2007

Reference Information

CVE: CVE-2007-3820, CVE-2007-4224, CVE-2007-4569

BID: 24912

CWE: 264, 59

RHSA: 2007:0905