Release date: 2011-10-12
Updated on: 2011-10-12
Affected Systems:
KDE 4.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-3365
KDE is a powerful open-source graphic desktop environment designed for UNIX workstations.
KDE has a security vulnerability in implementing the text format of KSSL certificates. Malicious users can exploit this vulnerability to perform spoofing attacks.
This vulnerability occurs when the certificate information is displayed, KSSL does not correctly set the text format, and spoofing the certificate by including specially crafted RTF data in the CN field.
<* Source: Tim Brown (securityfocus@machine.org.uk)
Link: http://www.kde.org/info/security/advisory-20111003-1.txt
Http://secunia.com/advisories/46157/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
KDE
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kde.org/