Red Hat Bugzilla – Bug 92144
CAN-2003-0370 KDE SSL CA checking implementation vulnerability
Last modified: 2007-11-30 17:06:53 EST
Versions of KDE 2.2.2 and earlier have a vulnerability in their SSL implementation that makes it possible for users of Konqueror and other SSL enabled KDE software to fall victim to a man-in-the-middle attack. Users of KDE should upgrade to the erratum packages currently in progress which will contain KDE 2.2.2 with a backported patch to correct this vulnerability. RHSA-2003:193 CVE applied for
An errata has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2003-193.html