Scientific Linux Security Update : kdelibs on SL5.x, SL4.x i386/x86_64
Medium Nessus Plugin ID 60263
SynopsisThe remote Scientific Linux host is missing one or more security updates.
DescriptionTwo cross-site-scripting flaws were found in the way Konqueror processes certain HTML content. This could result in a malicious attacker presenting misleading content to an unsuspecting user.
A flaw was found in the way Konqueror handled certain FTP PASV commands. A malicious FTP server could use this flaw to perform a rudimentary port-scan of machines behind a user's firewall.
Two Konqueror address spoofing flaws have been discovered. It was possible for a malicious website to cause the Konqueror address bar to display information which could trick a user into believing they are at a different website than they actually are. (CVE-2007-3820, CVE-2007-4224)
SolutionUpdate the affected kdelibs, kdelibs-apidocs and / or kdelibs-devel packages.