LWN.net Logo

kdelibs: certificate spoofing

Package(s):kdelibs CVE #(s):CVE-2011-3365 CVE-2011-3366
Created:October 11, 2011 Updated:November 10, 2011
Description: From the KDE advisory:

When displaying a security dialog with a certificate, KSSL does not properly force its QLabels to use QLabel::PlainText. As a result, if given a certificate containing rich text in its fields, it will render the rich text.

Specifically, a certificate containing a common name (CN) that has a table element will cause the second line of the table to be displayed. This can allow spoofing of the certificate's common name.

Alerts:
CentOS CESA-2011:1385 2011-11-09
Mandriva MDVSA-2011:162 2011-11-01
Ubuntu USN-1248-1 2011-10-25
Scientific Linux SL-kdel-20111019 2011-10-19
CentOS CESA-2011:1385 2011-10-19
Red Hat RHSA-2011:1385-01 2011-10-19
openSUSE openSUSE-SU-2011:1135-1 2011-10-17
Scientific Linux SL-kdel-20111011 2011-10-11
Red Hat RHSA-2011:1364-01 2011-10-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds