GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Fri Jun 27, 2014 3:26 pm Post subject: [ GLSA 201406-31 ] Konqueror: Multiple vulnerabilities |
|
|
Gentoo Linux Security Advisory
Title: Konqueror: Multiple vulnerabilities (GLSA 201406-31)
Severity: normal
Exploitable: remote
Date: June 27, 2014
Bug(s): #438452
ID: 201406-31
Synopsis
Multiple vulnerabilities have been found in Konqueror, the worst of
which may allow execution of arbitrary code.
Background
Konqueror is the KDE web browser and file manager.
Affected Packages
Package: kde-base/konqueror
Vulnerable: < 4.9.3-r1
Unaffected: >= 4.9.3-r1
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Konqueror. Please
review the CVE identifiers referenced below for details.
Impact
A remote attacker could entice a user to open a specially crafted web
site using Konqueror, possibly resulting in the execution of arbitrary
code with the privileges of the process or a Denial of Service condition
Workaround
There is no known workaround at this time.
Resolution
All Konqueror users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=kde-base/konqueror-4.9.3-r1"
| NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since November 11, 2012. It is likely that your system is
already no longer affected by this issue.
References
CVE-2012-4512
CVE-2012-4513
CVE-2012-4514
CVE-2012-4515 |
|