Bug 243617 (CVE-2007-2022) - CVE-2007-2022 kdebase3 flash-player interaction problem
Summary: CVE-2007-2022 kdebase3 flash-player interaction problem
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-2022
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 243618 243620 243622
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-06-10 20:37 UTC by Mark J. Cox
Modified: 2019-09-29 12:20 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-09-28 15:20:35 UTC
Embargoed:


Attachments (Terms of Use)
proposed patch (2.30 KB, patch)
2007-06-10 20:37 UTC, Mark J. Cox
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2007:0494 0 normal SHIPPED_LIVE Important: kdebase security update 2008-01-09 17:50:01 UTC

Description Mark J. Cox 2007-06-10 20:37:38 UTC
According to
        http://www.novell.com/linux/security/advisories/2007_12_sr.html

A problem with the interaction between the Flash Player and the Konqueror web
browser was fixed. The problem could lead to key presses leaking to the applet
instead of the browser. (CVE-2007-2022)

Patch from Dirk Mueller.

Comment 1 Mark J. Cox 2007-06-10 20:37:38 UTC
Created attachment 156673 [details]
proposed patch

Comment 2 Mark J. Cox 2007-06-11 08:57:03 UTC
See also 
        http://www.adobe.com/support/security/advisories/apsa07-03.html

Setting impact=important

Comment 3 Than Ngo 2007-06-11 20:25:05 UTC
it's fixed in 

Comment 6 Kurt Seifried 2011-09-28 15:20:35 UTC
This issue has been addressed in following products:

  Red Hat Linux Enterprise 3
  Red Hat Linux Enterprise 4
  Red Hat Linux Enterprise 4.5.z
  Red Hat Linux Enterprise 5

Via RHSA-2007:0494, https://rhn.redhat.com/errata/RHSA-2007-0494.html


Note You need to log in before you can comment on or make changes to this bug.