Fedora 10 Security Update: akonadi-1.2.1-1.fc10 et al

37
Article Source Fedora 10 Security Updates
September 8, 2009, 5:48 pm

Resolved Bugs
520661 – CVE-2009-2702 kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName
519654 – kdebase-workspace hijacks the gtk policykit authentication dialog

This updates KDE to 4.3.1, the latest upstream bugfix release. The main improvements are: * KDE 4.3 is now also available in Croatian. * A crash when editing toolbar setup has been fixed. * Support for transferring files through SSH using KIO::Fish has been fixed. * A number of bugs in KWin, KDE’s window and compositing manager has been fixed. * A large number of bugs in KMail, KDE’s email client are now gone. See http://kde.org/announcements/announce-4.3.1.php for more information. In addition, this update: * fixes a potential security issue (CVE-2009-2702) with certificate validation in the KIO KSSL code. It is believed that the affected code is not actually used (the code in Qt, for which a security update was already issued, is) and thus the issue is only potential, but KSSL is being patched just in case, * splits PolicyKit-kde out of kdebase-workspace again to avoid forcing it onto GNOME-based setups, where PolicyKit-gnome is desired instead (#519654)…

Read More