Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1111022 - (CVE-2014-3494) CVE-2014-3494 kdelibs: POP3 kioslave silently accepted invalid SSL certificates
CVE-2014-3494 kdelibs: POP3 kioslave silently accepted invalid SSL certificates
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20140617,repor...
: Security
Depends On: 1111023
Blocks: 1111025
  Show dependency treegraph
 
Reported: 2014-06-19 01:03 EDT by Murray McAllister
Modified: 2015-07-31 03:22 EDT (History)
12 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-08-04 05:34:42 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Murray McAllister 2014-06-19 01:03:25 EDT
The KDE project fixed the following issue:

""
Overview
========

The POP3 kioslave used by kmail will accept invalid certificates without
presenting a dialog to the user due a bug that leads to an inability to
display the dialog combined with an error in the way the result is checked.

Impact
======

This flaw allows an active attacker to perform MITM attacks against the
ioslave which could result in the leakage of sensitive data such as the
authentication details and the contents of emails.
""

Upstream notes this issue affected versions 4.10.95 to 4.13.2. It has been fixed in version 4.13.3. In addition to this, from an initial analysis it appears that only kdelibs in Fedora is affected (kdelibs3 should not be affected). kdelibs in Red Hat Enterprise Linux 5, 6, and 7 is older than the affected versions, and also appears to be missing the affected functionality.

Upstream advisory: http://www.kde.org/info/security/advisory-20140618-1.txt

Upstream commit: http://quickgit.kde.org/?p=kdelibs.git&a=commitdiff&h=bbae87dc1be3ae063796a582774bd5642cacdd5d&hp=1ccdb43ed3b32a7798eec6d39bb3c83a6e40228f
Comment 1 Murray McAllister 2014-06-19 01:04:30 EDT
Created kdelibs tracking bugs for this issue:

Affects: fedora-all [bug 1111023]
Comment 3 Fedora Update System 2014-07-01 03:23:28 EDT
kdelibs-4.12.5-4.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 4 Fedora Update System 2014-07-05 20:55:10 EDT
kdelibs-4.11.5-4.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.