Mandrake Linux Security Advisory : kdelibs/kdebase (MDKSA-2004:086)

High Nessus Plugin ID 14335


The remote Mandrake Linux host is missing one or more security updates.


A number of vulnerabilities were discovered in KDE that are corrected with these update packages.

The integrity of symlinks used by KDE are not ensured and as a result can be abused by local attackers to create or truncate arbitrary files or to prevent KDE applications from functioning correctly (CVE-2004-0689).

The DCOPServer creates temporary files in an insecure manner. These temporary files are used for authentication-related purposes, so this could potentially allow a local attacker to compromise the account of any user running a KDE application (CVE-2004-0690). Note that only KDE 3.2.x is affected by this vulnerability.

The Konqueror web browser allows websites to load web pages into a frame of any other frame-based web page that the user may have open.
This could potentially allow a malicious website to make Konqueror insert its own frames into the page of an otherwise trusted website (CVE-2004-0721).

The Konqueror web browser also allows websites to set cookies for certain country-specific top-level domains. This can be done to make Konqueror send the cookies to all other web sites operating under the same domain, which can be abused to become part of a session fixation attack. All country-specific secondary top-level domains that use more than 2 characters in the secondary part of the domain name, and that use a secondary part other than com, net, mil, org, gove, edu, or int are affected (CVE-2004-0746).


Update the affected packages.

See Also

Plugin Details

Severity: High

ID: 14335

File Name: mandrake_MDKSA-2004-086.nasl

Version: $Revision: 1.20 $

Type: local

Published: 2004/08/22

Modified: 2013/05/31

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:kdebase, p-cpe:/a:mandriva:linux:kdebase-common, p-cpe:/a:mandriva:linux:kdebase-kate, p-cpe:/a:mandriva:linux:kdebase-kcontrol-data, p-cpe:/a:mandriva:linux:kdebase-kdeprintfax, p-cpe:/a:mandriva:linux:kdebase-kdm, p-cpe:/a:mandriva:linux:kdebase-kdm-config-file, p-cpe:/a:mandriva:linux:kdebase-kmenuedit, p-cpe:/a:mandriva:linux:kdebase-konsole, p-cpe:/a:mandriva:linux:kdebase-nsplugins, p-cpe:/a:mandriva:linux:kdebase-progs, p-cpe:/a:mandriva:linux:kdelibs-common, p-cpe:/a:mandriva:linux:lib64kdebase4, p-cpe:/a:mandriva:linux:lib64kdebase4-devel, p-cpe:/a:mandriva:linux:lib64kdebase4-kate, p-cpe:/a:mandriva:linux:lib64kdebase4-kate-devel, p-cpe:/a:mandriva:linux:lib64kdebase4-kmenuedit, p-cpe:/a:mandriva:linux:lib64kdebase4-konsole, p-cpe:/a:mandriva:linux:lib64kdebase4-nsplugins, p-cpe:/a:mandriva:linux:lib64kdebase4-nsplugins-devel, p-cpe:/a:mandriva:linux:lib64kdecore4, p-cpe:/a:mandriva:linux:lib64kdecore4-devel, p-cpe:/a:mandriva:linux:libkdebase4, p-cpe:/a:mandriva:linux:libkdebase4-devel, p-cpe:/a:mandriva:linux:libkdebase4-kate, p-cpe:/a:mandriva:linux:libkdebase4-kate-devel, p-cpe:/a:mandriva:linux:libkdebase4-kmenuedit, p-cpe:/a:mandriva:linux:libkdebase4-konsole, p-cpe:/a:mandriva:linux:libkdebase4-nsplugins, p-cpe:/a:mandriva:linux:libkdebase4-nsplugins-devel, p-cpe:/a:mandriva:linux:libkdecore4, p-cpe:/a:mandriva:linux:libkdecore4-devel, cpe:/o:mandrakesoft:mandrake_linux:10.0, cpe:/o:mandrakesoft:mandrake_linux:9.2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2004/08/20

Reference Information

CVE: CVE-2004-0689, CVE-2004-0690, CVE-2004-0721, CVE-2004-0746

MDKSA: 2004:086