USN-150-1: KDE library vulnerability
===========================================================
Ubuntu Security Notice USN-150-1 July 21, 2005
kdelibs vulnerability
CAN-2005-1920
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.04 (Hoary Hedgehog)
The following packages are affected:
kdelibs4
The problem can be corrected by upgrading the affected package to
version 4:3.4.0-0ubuntu3.3. In general, a standard system upgrade is
sufficient to effect the necessary changes.
Details follow:
Kate and Kwrite create a backup file before saving a modified file.
These backup files were created with default permissions, even if the
original file had more strict permissions set, so that other local
users could possibly read the backup file even if they are not
permitted to read the original file.



