Submitted by KeesCook on Fri, 2007-08-24 19:02
Referenced CVEs:
CVE-2007-3820, CVE-2007-4224, CVE-2007-4225
Description:
===========================================================
Ubuntu Security Notice USN-502-1 August 23, 2007
kdebase, kdelibs vulnerabilities
CVE-2007-3820, CVE-2007-4224, CVE-2007-4225
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
kdelibs4c2a 4:3.5.2-0ubuntu18.5
konqueror 4:3.5.2-0ubuntu27.1
Ubuntu 6.10:
kdelibs4c2a 4:3.5.5-0ubuntu3.5
konqueror 4:3.5.5-0ubuntu3.5
Ubuntu 7.04:
kdelibs4c2a 4:3.5.6-0ubuntu14.1
konqueror 4:3.5.6-0ubuntu20.2
After a standard system upgrade you need to restart your session to
effect the necessary changes.
Details follow:
It was discovered that Konqueror could be tricked into displaying
incorrect URLs. Remote attackers could exploit this to increase their
chances of tricking a user into visiting a phishing URL, which could
lead to credential theft.


