KDE 3.5 Info Page
KDE 3.5 was released on November 29th, 2005. Read the official announcement.
Security Issues
Please report possible problems to security@kde.org.
Patches for the issues mentioned below are available from ftp://ftp.kde.org/pub/kde/security_patches unless stated otherwise.
- kpdf contains several buffer overflows in its xpdf-based code which can be triggered
by a specially crafted pdf file.
 Read the detailed advisory. All versions of KDE up to and including KDE 3.5.0 are affected.
- kjs contains a heap based buffer overflow when decoding certain malcrafted utf8
uri sequences.
 Read the detailed advisory. All versions of KDE starting with KDE 3.2.0 up to and including KDE 3.5.0 are affected.
- kpdf contains a buffer overflow in its xpdf-based code which can be triggered
by a specially crafted pdf file.
 Read the detailed advisory. All versions of KDE 3.3.0 up to and including KDE 3.5.1 are affected.
- KDM contains a symlink attack vulnerability that allows a normal
user to read files from other users including root.
 Read the detailed advisory. All versions of KDE starting with KDE 3.2.0 up to and including KDE 3.5.2 are affected.
- kpdf contains a denial of service vulnerability in xpdf based code that
can cause the client to crash via a specially crafted pdf file.
 Read the detailed advisory. All versions of KDE up to and including KDE 3.5.5 are affected.
- Konqueror contains a vulnerability that allows a malicious web site to spoof the address bar entry to a different one, possibly tricking the user into believing that they actually visited a different site. Read the detailed advisory. All versions of Konqueror as included with KDE up to including KDE 3.5.7 are affected.
- KDM can be tricked into allowing a passwordless login for logins with password configured. Read the detailed advisory. Versions of KDM as included in KDE 3.3.0 up to including 3.5.7 are affected.
Bugs
This is a list of grave bugs and common pitfalls surfacing after the release was packaged:
- None known yet
Please check the bug database before filing any bug reports. Also check for possible updates on this page that might describe or fix your problem.
FAQ
See the KDE FAQ for any specific questions you may have. Questions about Konqueror should be directed to the Konqueror FAQ.
Download and Installation
Library Requirements. KDE 3.5 requires or benefits from the given list of libraries, most of which should be already installed on your system or available from your OS CD or your vendor's website.
The complete source code for KDE 3.5 is available for download:
| Location | Size | MD5 Sum | 
|---|---|---|
| arts-1.5.0 | 927kB | e90a32ee47d5cdc51fe1b7f6f6c0df63 | 
| kdeaccessibility-3.5.0 | 8.0MB | f88f3340acdd219050759df86e3d97d0 | 
| kdeaddons-3.5.0 | 1.5MB | a61bcb10580208c3abb8c47aed198597 | 
| kdeadmin-3.5.0 | 2.0MB | 9d0f914d2d0d3fbef8ed51cfdab36d40 | 
| kdeartwork-3.5.0 | 15MB | 052c736c9c12defbb2e7de04ff0b2ae6 | 
| kdebase-3.5.0 | 22MB | b86622c029ee8ab656a67c6467fff887 | 
| kdebindings-3.5.0 | 5.1MB | 137924318ff5fc49cee3c82ee0ce5cf5 | 
| kdeedu-3.5.0 | 28MB | ac66cfcc8e23227973596cf62cf78a4c | 
| kdegames-3.5.0 | 9.8MB | ba86fe9280ca57698ce3be0e0242b140 | 
| kdegraphics-3.5.0 | 6.7MB | 389a00d4387e621d4dd325a59c7657c4 | 
| kdelibs-3.5.0 | 14MB | 2b11d654e2ea1a3cd16dcfdcbb7d1915 | 
| kdemultimedia-3.5.0 | 5.2MB | dd0ba9ccb2f522508c6543cd24e54c98 | 
| kdenetwork-3.5.0 | 7.1MB | c83dce8cc496b6ec8773483df1c85119 | 
| kdepim-3.5.0 | 12MB | e19a2a40e422ecd483884ce6e9ac8925 | 
| kdesdk-3.5.0 | 4.6MB | dc91ffcfa8114cf4f9d40bc9ffe47d97 | 
| kdetoys-3.5.0 | 3.0MB | aebe4a9586728b37543bd515d35e76e1 | 
| kdeutils-3.5.0 | 2.8MB | d6b2cbe8b7d15166eff261f20ece2718 | 
| kdevelop-3.3.0 | 7.7MB | 1048c89c1aad0daf6581bb04e15206c4 | 
| kdewebdev-3.5.0 | 5.7MB | 58bb4d025fa125c5ad0dc43769ba9786 | 
The Konstruct build toolset can help you downloading and installing these tarballs.
Some Linux/UNIX OS vendors have kindly provided binary packages of KDE 3.5 for some versions of their distribution, and in other cases community volunteers have done so. Some of these binary packages are available for free download from KDE's http or FTP mirrors.
Currently pre-compiled packages are available for:
- Arch Linux
:- Packages: ftp://ftp.archlinux.org/extra/os/i686
- To install: pacman -S kde
 
- Kubuntu- Breezy: Intel i386 and AMD64
 
- Slackware (Unofficial contribution)
(README)
:- Language packages
- 10.2: Intel i486
- 10.1: Intel i486
 
- SuSE Linux
(README)
:- Language packages (all versions and architectures)
- 10.0: Intel i586 and AMD x86-64
- 9.3: Intel i586 and AMD x86-64
- 9.2: Intel i586 and AMD x86-64
- 9.1: Intel i586 and AMD x86-64
 
Additional binary packages might become available in the coming weeks, as well as updates to the current packages.
Developer Info
If you need help porting your application to KDE 3.x see the porting guide or subscribe to the KDE Devel Mailinglist to ask specific questions about porting your applications.
There is also info on the architecture and the programming interface of KDE 3.5.