USN-3042-1: KDE-Libs vulnerability

Publication date

26 July 2016

Overview

KDE-Libs could be made to overwrite files.


Packages

  • kde4libs - KDE 4 core applications and libraries

Details

Andreas Cord-Landwehr discovered that KDE-Libs incorrectly handled
extracting certain archives. If a user were tricked into extracting a
specially-crafted archive, a remote attacker could use this issue to
overwrite arbitrary files out of the extraction directory.

Andreas Cord-Landwehr discovered that KDE-Libs incorrectly handled
extracting certain archives. If a user were tricked into extracting a
specially-crafted archive, a remote attacker could use this issue to
overwrite arbitrary files out of the extraction directory.

Update instructions

After a standard system update you need to reboot your computer to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
15.10 wily libkdecore5 –  4:4.14.13-0ubuntu1.1
14.04 trusty libkdecore5 –  4:4.13.3-0ubuntu0.3
12.04 precise libkdecore5 –  4:4.8.5-0ubuntu0.5

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›