DesktopLinux
Home  |  News  |  Articles  |  Forum  |  Polls  |  Blogs  |  Videos  |  Resource Library

Keywords: Match:
KDE issues fix for flawed patches
May 20, 2005

Late last month, K Desktop Environment (KDE) developers announced the discovery of a serious vulnerability in KDE versions 3.2 through 3.4. A patch was issued, but the patch itself is faulty and introduces new vulnerabilities. This week, KDE issued another patch to patch the patch.

On April 20, KDE released a patch for a vulnerability Kommander, which allows scripts to run arbitrary code without user confirmation. Another patch, released April 21, attempted to eliminate vulnerabilities in kimgio, which allows the execution of malicious code through "specially-crafted" images.

An advisory this week reveals that both patches were flawed. The patch for kimgio broke some functionality, while the patch for Kommander was simply ineffective.

Fixes for both patches are available now via FTP.

Visit the KDE Security Advisories page to learn more about these and other KDE security issues.



Related Stories:


(Click here for further information)



Home  |  News  |  Articles  |  Forum  |  Polls  |  About  |  Contact
 

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
Tech RSS Feeds | ROI Calculators | Tech Podcasts | Tech Video | VARs | Channel News

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | Enterprise Network Security | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | Security IT Hub | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | igrep

Use of this site is governed by our Terms of Service and Privacy Policy. Except where otherwise specified, the contents of this site are copyright © 1999-2011 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise is prohibited. Linux is a registered trademark of Linus Torvalds. All other marks are the property of their respective owners.