kdelibs3-3.5.10-84.fc24

This kdelibs3 (KDE 3 compatibility libraries) update fixes the security issues:

* CVE-2016-6232 (karchive): Extraction of tar files possible to arbitrary system locations
* CVE-2017-6410 (kio): Information Leak when accessing https when using a malicious PAC file

for the KDE 3 compatibility libraries. (Security updates for KDE Frameworks 5 (kf5-karchive resp. kf5-kio) and for the KDE 4 compatibility libraries (kdelibs 4) have already been submitted.)

In addition, the KDE 3 compatibility version of KCrash was modified to use the DrKonqi from Plasma 5 rather than from kde-runtime 4. (The original KDE 3 DrKonqi was already dropped years ago.) The kde-runtime 4 DrKonqi is not installed by default and will be removed entirely in future Fedora versions, the Plasma 5 version of DrKonqi can also be used for legacy applications.

Leave a Reply