Summary
The remote host is missing an update as announced
via advisory SSA:2007-264-01.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=SSA:2007-264-01
Insight
New kdebase packages are available for Slackware 12.0 to fix security issues.
A long URL padded with spaces could be used to display a false URL in Konqueror's addressbar, and KDM when used with no-password login could be tricked into logging a different user in without a password. This is not the way KDM is configured in Slackware by default, somewhat mitigating the impact of this issue.
More details about the issues may be found here:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3820 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4224 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4225 http://www.kde.org/info/security/advisory-20070919-1.txt http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4569 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4225
Severity
Classification
-
CVE CVE-2007-3820, CVE-2007-4224, CVE-2007-4225, CVE-2007-4569 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities