| From: |
| Jamie Strandboge <jamie@canonical.com> |
| To: |
| ubuntu-security-announce@lists.ubuntu.com |
| Subject: |
| [USN-833-1] KDE-Libs vulnerability |
| Date: |
| Thu, 17 Sep 2009 19:53:21 -0500 |
| Message-ID: |
| <20090918005321.GA4643@severus.strandboge.com> |
| Cc: |
| bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk |
| Archive-link: |
| Article, Thread
|
===========================================================
Ubuntu Security Notice USN-833-1 September 18, 2009
kde4libs, kdelibs vulnerability
CVE-2009-2702
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
kdelibs4c2a 4:3.5.10-0ubuntu1~hardy1.3
Ubuntu 8.10:
kdelibs4c2a 4:3.5.10-0ubuntu6.2
kdelibs5 4:4.1.4-0ubuntu1~intrepid1.3
Ubuntu 9.04:
kdelibs4c2a 4:3.5.10.dfsg.1-1ubuntu8.2
kdelibs5 4:4.2.2-0ubuntu5.2
After a standard system upgrade you need to restart your session to effect
the necessary changes.
Details follow:
It was discovered that KDE did not properly handle certificates with NULL
characters in the Subject Alternative Name field of X.509 certificates. An
attacker could exploit this to perform a man in the middle attack to view
sensitive information or alter encrypted communications.
Updated packages for Ubuntu 8.04 LTS:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 1793069 187ec3a85ab66aee01bcb2e27e6c9272
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 1729 ccd84021e8ade302e4b5095ea0572666
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 18631467 5eeb6f132e386668a0395d4d426d495e
Architecture independent packages:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 7326466 50dad4adb64e3301c768e72b3e097b67
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 25452634 3e7c3ea25126981a173726a130078c58
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 9324 728e2cb96c373e63fdfee56a4dd1e702
amd64 architecture (Athlon64, Opteron, EM64T Xeon):
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 26757976 f8eef85b999d55fba33308880e27be7c
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 1381574 92a6204e34af44d3ccfe8dc2e8d01fb5
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 10656446 655ec0415ce4a852a12fdd1156a3eca8
i386 architecture (x86 compatible Intel/AMD):
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 25991290 c1d804454072afe2e71d6eb5bb3dc05f
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 1410722 7c741099f303295987ef7b0524274e63
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 9614700 93a582e847eab24063c11ad605b10142
lpia architecture (Low Power Intel Architecture):
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs-dbg_3...
Size/MD5: 25971054 6b61c2978e639b7835b01ae06cbd9a2e
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4-dev_...
Size/MD5: 1375930 00ecd9ca7f29b73556e9f6c3bf981fc2
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4c2a_3...
Size/MD5: 9642886 2d8ae1faa029eabb702b70a76630739e
powerpc architecture (Apple Macintosh G3/G4/G5):
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs-dbg_3...
Size/MD5: 27657094 2dc35ad444e8734c59fba4ca56774e8f
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4-dev_...
Size/MD5: 1393530 f83a37075ab830031facb712a9da9da4
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4c2a_3...
Size/MD5: 10453566 5013cc7e9c7e115eab9cd9fde9118ff7
sparc architecture (Sun SPARC/UltraSPARC):
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs-dbg_3...
Size/MD5: 25026348 4a18b96bd2a85c45ce9d7158a11c4ec4
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4-dev_...
Size/MD5: 1376520 eab1553c8f268157efb2b53adacc661c
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4c2a_3...
Size/MD5: 9596382 687fe06b9bc8792ef6a069978f59b309
Updated packages for Ubuntu 8.10:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 94463 20f3f048b48a6154c94347684d939be8
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 2308 43c30f314024ddb8432cf54f1a59ac39
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 11190299 18264580c1d6d978a3049a13fda36f29
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 725675 ffb7c97c7f032cfe364de5b842bf61f6
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 2284 ae968b002f97aae75fd793cb8de9d39e
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 18631467 5eeb6f132e386668a0395d4d426d495e
Architecture independent packages:
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 3110716 df4982bfbe3fd3c9cf1c947738d79169
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 68732 1b23694bd9338a28f62fb8f91b568c8c
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 7321458 07c8b9bfd2748743f96af783b77a224d
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 25521766 e25073540a1dc08f0e819ba455e02c70
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 2266 b8f8e6cd0d7b32be032550ad35845ba9
amd64 architecture (Athlon64, Opteron, EM64T Xeon):
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 395542 75d4757b42bf89d16b2c16e7d43f5ada
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 66055482 09eac19437b874b66cf1b4db0c6d569e
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 1440678 e2dd6be4b652233dbcec0da92ac474dd
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 10104548 c8e7d22348175343122878c7b82f949d
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 27376716 3d224181ea5776e7d6bab0c15b60ee40
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 1371470 b5ac9d9d2e168757978ca26d9df20f61
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 10930140 d9ae96a01fef782091e07cc12b921391
i386 architecture (x86 compatible Intel/AMD):
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 371688 08ec03f83f7f4e84efff38df60346ccc
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 65218344 ced032e207e7a46c03ac88c3d6e9b548
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 1438144 2c1b0b248ab054f0f345c9cbca3a3e44
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 9524304 845be524702f29b6ab4d1dffe967c51a
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 26665858 5a6094e745465ae189ed9b1b312401ce
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 1404998 c22d9bb0867f1c663a99ca2c848e22e8
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 10143854 79e8fffc3fe41b6385fbad5275fded72
lpia architecture (Low Power Intel Architecture):
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs-bin_...
Size/MD5: 376514 3ddcad28190c298aa83631d7bb031710
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dbg...
Size/MD5: 65334416 236a09dd3b960a5eabdea7605a438817
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dev...
Size/MD5: 1440690 e385f33b72b1f8f4f4a53def294feca6
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5_4.1...
Size/MD5: 9536508 ef0abc0f2575f360c4eabe2ac756b9ec
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs-dbg_3...
Size/MD5: 26675042 cdfd48553d95a07e9635ff08d98c43b6
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4-dev_...
Size/MD5: 1368274 cfa22989df6350951dac74601a155c0f
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4c2a_3...
Size/MD5: 10141526 eb34d77357d8f2526cb6efaeaee5498e
powerpc architecture (Apple Macintosh G3/G4/G5):
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs-bin_...
Size/MD5: 422968 269f03f1b9721565b563d64ec71c25be
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dbg...
Size/MD5: 69278622 7add4570902ce8560f3f18b0f1208792
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dev...
Size/MD5: 1445646 b6b5579e7ffe46d4f310ed4ee1141406
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5_4.1...
Size/MD5: 10239520 aad1f8aefee57d23e5a026e75cf2a91b
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs-dbg_3...
Size/MD5: 28218136 9729576385b7a182dd5d0a22a24f866a
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4-dev_...
Size/MD5: 1380872 a2075d2cb88c81ecf584b270112f07d4
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4c2a_3...
Size/MD5: 10748976 e83ab4816e89c0c33fa6e0ab650059f3
sparc architecture (Sun SPARC/UltraSPARC):
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs-bin_...
Size/MD5: 381288 ade230bccfa0ef83884b019b87753158
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dbg...
Size/MD5: 64517758 cf2f9aa5d6d7e36a4782344701eeca75
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dev...
Size/MD5: 1437794 8a044c29537b6c1a7b64ea2fea8b1fdd
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5_4.1...
Size/MD5: 9654364 88591122cd6c8bc6113ece6d344c7d51
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs-dbg_3...
Size/MD5: 25440976 1adec7a267c7fef4108f1ce7e0479e13
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4-dev_...
Size/MD5: 1368494 696ba573b43e52c7e389560d6df95b2c
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4c2a_3...
Size/MD5: 9801638 a353b425dadaf84e012d2ab5ba400f7e
Updated packages for Ubuntu 9.04:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 103065 43ccd7fc8a6a0f8f97dc4e6271707dca
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 2305 e2ecbb116baa42ec1b62d42a0677ad70
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 12335659 83d6a0d59e79873bbe0a5a90ef23f27e
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 729309 513f26f3d382d8fedbee190436486328
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 2342 ad777f2449c735eca36b3cc13d7a51ca
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 18639393 4bcfee29b0f939415791f5032a72e7b0
Architecture independent packages:
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 1993082 42ef0a82e00ae2b3143536725cc23d59
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 6751922 9de426e7cf252b225ea227cb4cf91f27
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 2266 928abd6b4205730964c0c195f61a9f8d
amd64 architecture (Athlon64, Opteron, EM64T Xeon):
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 280894 2fec52b6f5031e0876de243f7e7ee5cd
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 44162076 1f3b61fedfc843e1037f810900d1949b
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 1091326 da10eb01a684aa1bf182c64c20fa4aba
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 7069506 e72c27cadd57b3a88f23fddae41a7ffc
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/li...
Size/MD5: 102494 0111512a28e9bf91ebe7480d91071631
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/li...
Size/MD5: 610810 f45f1ffa2a5301696d143ba71a0f0dac
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 27110174 197340cb71ca249e4df7488f9944c536
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 1360046 09720667dccb979e1820dc34e151da93
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 10782498 72aeb55d413d2953fc4f58af7bf9df02
i386 architecture (x86 compatible Intel/AMD):
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 268854 c997bd77e73aff36045aa67a8de4d1a6
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 43459352 7ec8c9ed7910d75b7e7ce1169a78ffdf
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 1090322 58985d758a9d9b62b03375fc0f53f678
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/kd...
Size/MD5: 6782992 45b60a6f6e1f95386203ca7de916874b
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/li...
Size/MD5: 126988 2c8a64d0a546f97cbf30c0d331032471
http://security.ubuntu.com/ubuntu/pool/main/k/kde4libs/li...
Size/MD5: 567930 82dd739cbcbd0ff6819b8d6f22a8b699
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 26383518 8ea6b553b590d2f981eed71b99b5e7c2
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 1394880 651f06f64958882052d40ae34aad94d4
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kde...
Size/MD5: 10006524 960e4d01c61acdeb6fbe1d347b4584e5
lpia architecture (Low Power Intel Architecture):
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs-bin_...
Size/MD5: 275800 3f5daf63e12944aa2b77fcf08f71bcb4
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dbg...
Size/MD5: 43581740 2a75a567ad13026c121972b6582d0528
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dev...
Size/MD5: 1092574 69b56fe3007d0242f0939313d3bfbe9a
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5_4.2...
Size/MD5: 6845370 165fc2e04936fe422045a27e7fb58704
http://ports.ubuntu.com/pool/main/k/kde4libs/libplasma-de...
Size/MD5: 102456 8679f4d3f47f6f9930e6a7c0c0a4681a
http://ports.ubuntu.com/pool/main/k/kde4libs/libplasma3_4...
Size/MD5: 599148 7aeaf303e28e4b81922b5825138c7e5a
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs-dbg_3...
Size/MD5: 26385502 4c44b69f55edd6ff4e9d42034c399639
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4-dev_...
Size/MD5: 1356816 140662c1f2cb4761adabb8c4baf91674
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4c2a_3...
Size/MD5: 10020434 3d2f381e7c146ea888697eb0a5461705
powerpc architecture (Apple Macintosh G3/G4/G5):
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs-bin_...
Size/MD5: 269354 86bc3cccc81ac1c3234ce15e0fe1c7a9
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dbg...
Size/MD5: 43131400 bc75ffe4a5c5f1c6022450169d88d10c
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dev...
Size/MD5: 1089860 3fd66c006f70506f4955fbbf8df3fac2
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5_4.2...
Size/MD5: 6207048 3d06ac2cf2f97d2d501d08276145aa6b
http://ports.ubuntu.com/pool/main/k/kde4libs/libplasma-de...
Size/MD5: 102480 d1c67ddde176471e7ed014873a315d04
http://ports.ubuntu.com/pool/main/k/kde4libs/libplasma3_4...
Size/MD5: 555276 7f02da15764a251ff0d87526fdee909e
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs-dbg_3...
Size/MD5: 27928494 37150bb80f2029257ddab765e671d255
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4-dev_...
Size/MD5: 1369344 20c5e9b2db7700c1797c216fd679d7aa
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4c2a_3...
Size/MD5: 10611464 4c1e7146338d3b5d1b4e11787ab3fb55
sparc architecture (Sun SPARC/UltraSPARC):
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs-bin_...
Size/MD5: 249888 cad7d47cc258c2b61278eb5102fd7456
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dbg...
Size/MD5: 40333098 831fc3566c8baf33697b4145808827b2
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5-dev...
Size/MD5: 1086120 08944df70fb96ac3e3d86676dea28c21
http://ports.ubuntu.com/pool/main/k/kde4libs/kdelibs5_4.2...
Size/MD5: 5942468 91fd699fcee3c49d5e6ad77d1501c4e4
http://ports.ubuntu.com/pool/main/k/kde4libs/libplasma-de...
Size/MD5: 102492 48f6f99013a24a6ef3683646e08f7aa5
http://ports.ubuntu.com/pool/main/k/kde4libs/libplasma3_4...
Size/MD5: 529960 2e66892a85327c8e063975711f8f0137
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs-dbg_3...
Size/MD5: 25158570 047b59e2249d3ee1545ea795faca12e8
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4-dev_...
Size/MD5: 1356982 90bae40d56c4e60af9dbeb5e7f008b69
http://ports.ubuntu.com/pool/main/k/kdelibs/kdelibs4c2a_3...
Size/MD5: 9663630 0926261754815f790c15d42e3206747a
(
Log in to post comments)