Oracle Linux 4 / 5 : kdebase (ELSA-2007-0905)

Medium Nessus Plugin ID 67573

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

From Red Hat Security Advisory 2007:0905 :

Updated kdebase packages that resolve several security flaws are now available for Red Hat Enterprise Linux 4 and 5.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

The kdebase packages provide the core applications for KDE, the K Desktop Environment. These core packages include Konqueror, the web browser and file manager.

These updated packages address the following vulnerabilities :

Kees Huijgen found a flaw in the way KDM handled logins when autologin and 'shutdown with password' were enabled. A local user would have been able to login via KDM as any user without requiring a password.
(CVE-2007-4569)

Two Konqueror address spoofing flaws were discovered. A malicious website could spoof the Konqueror address bar, tricking a victim into believing the page was from a different site. (CVE-2007-3820, CVE-2007-4224)

Users of KDE should upgrade to these updated packages, which contain backported patches to correct these issues.

Solution

Update the affected kdebase packages.

See Also

https://oss.oracle.com/pipermail/el-errata/2007-October/000355.html

https://oss.oracle.com/pipermail/el-errata/2007-October/000358.html

Plugin Details

Severity: Medium

ID: 67573

File Name: oraclelinux_ELSA-2007-0905.nasl

Version: 1.12

Type: local

Agent: unix

Published: 2013/07/12

Updated: 2018/07/18

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:linux:kdebase, p-cpe:/a:oracle:linux:kdebase-devel, cpe:/o:oracle:linux:4, cpe:/o:oracle:linux:5

Required KB Items: Host/local_checks_enabled, Host/OracleLinux, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2007/10/08

Vulnerability Publication Date: 2007/07/13

Reference Information

CVE: CVE-2007-3820, CVE-2007-4224, CVE-2007-4569

BID: 24912

RHSA: 2007:0905

CWE: 59, 264