Package name
Advisory ID
Affected versions
8.0 i586

Problem description

A problem exists with the kdesu component of kdelibs. It created a world-readable temporary file to exchange authentication information and delete it shortly after. This can be abused by a local user to gain access to the X server and could result in a compromise of the account that kdesu would access. Update: The previous update broke sound support under KDE. This update resolves the problem.

Updated packages

8.0 i586

 0270b302c84ce3bc6802348c89572585  8.0/RPMS/arts-2.1.2-3mdk.i586.rpm
6a8d148dd5de24857a34c6c3c3dfa74c  8.0/RPMS/kdelibs-2.1.2-3mdk.i586.rpm
5b9e10cbfed7cd2fa278bf30279df569  8.0/RPMS/kdelibs-devel-2.1.2-3mdk.i586.rpm
cfd2d950c44fbb662bd27adfe111fdb2  8.0/RPMS/kdelibs-devel-static-libraries-2.1.2-3mdk.i586.rpm
a1b7b96d5525b0c36d9645f43452a4ac  8.0/RPMS/libarts2-2.1.2-3mdk.i586.rpm
8dcb076115765a853fbefc5d92a27c3b  8.0/RPMS/libarts2-devel-2.1.2-3mdk.i586.rpm
5ef1a888353f45faef0ad73d54e551cc  8.0/SRPMS/kdelibs-2.1.2-3mdk.src.rpm