| KDE issues fix for flawed patches |
May 20, 2005
Late last month, K Desktop Environment (KDE) developers announced the discovery of a serious vulnerability in KDE versions 3.2 through 3.4. A patch was issued, but the patch itself is faulty and introduces new vulnerabilities. This week, KDE issued another patch to patch the patch.
On April 20, KDE released a patch for a vulnerability Kommander, which allows scripts to run arbitrary code without user confirmation. Another patch, released April 21, attempted to eliminate vulnerabilities in kimgio, which allows the execution of malicious code through "specially-crafted" images.
An advisory this week reveals that both patches were flawed. The patch for kimgio broke some functionality, while the patch for Kommander was simply ineffective.
Fixes for both patches are available now via FTP.
Visit the KDE Security Advisories page to learn more about these and other KDE security issues.
Related Stories:
(Click here for further information)
|
|
|
|
|
|
|
|