USN-872-1: KDE 4 Runtime vulnerabilities
11 December 2009
KDE 4 Runtime vulnerabilities
Releases
Packages
Details
It was discovered that the KIO subsystem of KDE did not properly perform
input validation when processing help:// URIs. If a user or KIO application
processed a crafted help:// URI, an attacker could trigger JavaScript
execution or access files via directory traversal.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 9.04
Ubuntu 8.10
After a standard system upgrade you need to restart your session to effect
the necessary changes.