PT-2011-1143 · Kde+1 · Kdelibs+2

Published

2011-10-11

·

Updated

2023-02-13

·

CVE-2011-3365

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions kdelibs versions 3.3.1 through 3.5.4 kdelibs versions prior to 4.12.5-r1 KDE SC versions 4.6.0 through 4.7.1
Description The issue allows remote attackers to exploit vulnerabilities in the kdelibs package, potentially leading to a breach of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited remotely. The KDE SSL Wrapper (KSSL) API does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.
Recommendations For kdelibs versions 3.3.1 through 3.5.4, update to a version outside of this range to mitigate the risk. For kdelibs versions prior to 4.12.5-r1, update to version 4.12.5-r1 or later to resolve the issue. For KDE SC versions 4.6.0 through 4.7.1, consider disabling the KSSL API until a patch is available. As a temporary workaround, restrict access to the vulnerable kdelibs package to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2015-07269
BDU:2015-07270
BDU:2015-07271
BDU:2015-07274
BDU:2015-07275
BDU:2015-08795
BDU:2015-08796
BDU:2015-08797
BDU:2015-08798
BDU:2015-08799
BDU:2015-09700
CVE-2011-3365
RHSA-2011:1364
RHSA-2011:1385
RHSA-2011_1364
RHSA-2011_1385

Affected Products

Kde Sc
Red Hat
Kdelibs