Chapter 1. Package Updates
112
allows users to mount and unmount volumes through the storage devices detected by the HAL.
(
BZ#469723
750
)
• previously, when KDE refreshed desktop icons, it did not refresh the list of icons that it should
display on the desktop. As a consequence, icons could appear on the desktop even when the file
that they represented had been deleted, and refreshing the desktop would not remove these icons.
This situation could arise, for example, when viewing files on an NFS share. When KDE refreshes
its view of the desktop, it now updates the list of icons first and therefore avoids drawing icons for
non-existent files. (
BZ#472295
751
)
All KDE users are advised to upgrade to these updated packages, which resolve these issues.
1.106. kdegraphics
1.106.1. RHSA-2009:1130: Critical security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:1130
752
Updated kdegraphics packages that fix two security issues are now available for Red Hat Enterprise
Linux 5.
This update has been rated as having critical security impact by the Red Hat Security Response
Team.
The kdegraphics packages contain applications for the K Desktop Environment (KDE). Scalable
Vector Graphics (SVG) is an XML-based language to describe vector images. KSVG is a framework
aimed at implementing the latest W3C SVG specifications.
A use-after-free flaw was found in the KDE KSVG animation element implementation. A remote
attacker could create a specially-crafted SVG image, which once opened by an unsuspecting user,
could cause a denial of service (Konqueror crash) or, potentially, execute arbitrary code with the
privileges of the user running Konqueror. (
CVE-2009-1709
753
)
A NULL pointer dereference flaw was found in the KDE, KSVG SVGList interface implementation.
A remote attacker could create a specially-crafted SVG image, which once opened by an
unsuspecting user, would cause memory corruption, leading to a denial of service (Konqueror crash).
(
CVE-2009-0945
754
)
All users of kdegraphics should upgrade to these updated packages, which contain backported
patches to correct these issues. The desktop must be restarted (log out, then log back in) for this
update to take effect.
753
https://www.redhat.com/security/data/cve/CVE-2009-1709.html
754
https://www.redhat.com/security/data/cve/CVE-2009-0945.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...