Bugzilla – Bug 1124863
VUL-0: CVE-2019-7443: kauth: Insecure handling of arguments in helpers
Last modified: 2019-12-17 13:19:07 UTC
https://www.kde.org/info/security/advisory-20190209-1.txt: KDE Project Security Advisory ============================= Title: kauth: Insecure handling of arguments in helpers Risk Rating: Medium CVE: CVE-2019-7443 Versions: KDE Frameworks < 5.55.0 Date: 9 February 2019 Overview ======== KAuth allows to pass parameters with arbitrary types to helpers running as root over DBus. Certain types can cause crashes and trigger decoding arbitrary images with dynamically loaded plugins. Solution ======== Update to kauth >= 5.55.0 Or apply the following patch to kauth: https://cgit.kde.org/kauth.git/commit/?id=fc70fb0161c1b9144d26389434d34dd135cd3f4a Credits ======= Thanks to Fabian Vogt for the report and Albert Astals Cid for the fix.
This is an autogenerated message for OBS integration: This bug (1124863) was mentioned in https://build.opensuse.org/request/show/672994 15.0+42.3+Backports:SLE-12-SP1+Backports:SLE-12-SP2+Backports:SLE-12-SP3+Backports:SLE-15 / kauth
This is an autogenerated message for OBS integration: This bug (1124863) was mentioned in https://build.opensuse.org/request/show/673427 15.0+42.3+Backports:SLE-12-SP1+Backports:SLE-12-SP2+Backports:SLE-12-SP3+Backports:SLE-15 / kauth
openSUSE-SU-2019:0242-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1124863 CVE References: CVE-2019-7443 Sources used: openSUSE Leap 42.3 (src): kauth-5.32.0-3.3.1 openSUSE Leap 15.0 (src): kauth-5.45.0-lp150.3.3.1 openSUSE Backports SLE-15 (src): kauth-5.45.0-bp150.3.3.1
openSUSE-SU-2019:0242-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1124863 CVE References: CVE-2019-7443 Sources used: openSUSE Leap 42.3 (src): kauth-5.32.0-3.3.1 openSUSE Leap 15.0 (src): kauth-5.45.0-lp150.3.3.1 openSUSE Backports SLE-15 (src): kauth-5.45.0-bp150.3.3.1 SUSE Package Hub for SUSE Linux Enterprise 12 (src): kauth-5.20.0-10.1, kauth-5.20.0-10.2, kauth-5.26.0-9.2, kauth-5.26.0-9.3, kauth-5.32.0-5.1, kauth-5.32.0-5.2, kcoreaddons-5.20.0-8.1, kcoreaddons-5.26.0-5.2, kcoreaddons-5.26.0-5.4, kcoreaddons-5.32.0-7.1, polkit-qt5-1-0.112.0-2.1, polkit-qt5-1-0.112.0-2.2, polkit-qt5-1-0.112.0-4.1, polkit-qt5-1-0.112.0-5.1
openSUSE-SU-2019:0247-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1124863 CVE References: CVE-2019-7443 Sources used: openSUSE Backports SLE-15 (src): kauth-5.45.0-bp150.3.6.1
openSUSE-SU-2019:1051-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1124863 CVE References: CVE-2019-7443 Sources used: openSUSE Backports SLE-15 (src): kauth-5.32.0-bp150.3.10.1, kcoreaddons-5.32.0-bp150.3.3.1, polkit-qt5-1-0.112.0-bp150.3.3.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:1277-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1124863 CVE References: CVE-2019-7443 Sources used: openSUSE Backports SLE-15 (src): kauth-5.45.0-bp150.8.2, polkit-qt5-1-0.112.0-bp150.3.6.1, polkit-qt5-1-0.112.0-bp150.3.6.2
This is automated batch bugzilla cleanup. The openSUSE 42.3 changed to end-of-life (EOL [1]) status. As such it is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of openSUSE (At this moment openSUSE Leap 15.1, 15.0 and Tumbleweed) please feel free to reopen this bug against that version (!you must update the "Version" component in the bug fields, do not just reopen please), or alternatively create a new ticket. Thank you for reporting this bug and we are sorry it could not be fixed during the lifetime of the release. [1] https://en.opensuse.org/Lifetime
fixed
Said to also affect kdelibs4 which is still maintained in some code streams. Evaluation needed.