CVE-2011-3365

Publication date 3 October 2011

Last updated 24 July 2024


Ubuntu priority

The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

From the Ubuntu Security Team

Tim Brown discovered that KSSL in KDE-Libs did not properly perform input validation when displaying the common name (CN) for an SSL certificate. An attacker could exploit this to spoof the common name which could be used in an attack to trick the user into accepting a fraudulent certificate.

Read the notes from the security team

Status

Package Ubuntu Release Status
kde4libs 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Fixed 4:4.5.5-0ubuntu2.1
10.04 LTS lucid
Fixed 4:4.4.5-0ubuntu1.2
8.04 LTS hardy Ignored end of life

Notes


jdstrand

also want 90607b28d21fefc43657ca08b889bdb174c31fab

References

Related Ubuntu Security Notices (USN)

    • USN-1248-1
    • KDE-Libs vulnerability
    • 25 October 2011

Other references