BugTraq
KDE Security Advisory: Multiple vulnerabilities in KDE Dec 21 2002 12:13PM
Dirk Mueller (mueller kde org) (1 replies)
Re: KDE Security Advisory: Multiple vulnerabilities in KDE Dec 22 2002 11:07PM
fozzy dmpfrance com (1 replies)

> The KDE Project is not aware of any existing exploits of these
> vulnerabilities

I'd like to stress out that, due to the nature of these vulnerabilities,
exploitation can be very easy and "basic". Security-enhanced kernels
(preventing buffer overflows and format string attacks) will not help. A
bit like most MS Internet Explorer bugs BTW... ;-)
After I found out some of these problems, the KDE Security Team has done a
good job in finding and fixing all the potentially vulnerable instances of
code. This is a major fix, so consider upgrading soon !

Fozzy

The Hackademy Audit
http://www.thehackademy.net/audit.php (french)

[ reply ]
Re: KDE Security Advisory: Multiple vulnerabilities in KDE Dec 23 2002 06:40PM
Florian Weimer (Weimer CERT Uni-Stuttgart DE)


 

Privacy Statement
Copyright 2010, SecurityFocus