Family: Debian Local Security Checks --> Category: infos
[DSA459] DSA-459-1 kdelibs Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
A vulnerability was discovered in KDE where the path restrictions on
cookies could be bypassed using encoded relative path components
(e.g., "/../"). This means that a cookie which should only be sent by
the browser to an application running at /app1, the browser could
inadvertently include it with a request sent to /app2 on the same
For the current stable distribution (woody) this problem has been
fixed in kdelibs version 4:2.2.2-6woody3 and kdelibs-crypto version
For the unstable distribution (sid) this problem was fixed in kdelibs
We recommend that you update your kdelibs and kdelibs-crypto packages.
Solution : http://www.debian.org/security/2004/dsa-459
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.