Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE: 2018:0398-1 Important Security Fix for Plasma5-Workspace

opensuse
Calendar Grey February 8, 2018
Dist Opensuse Esm H88
Vital openSUSE patch tackles two significant flaws in plasma5-workspace to bolster security measures.
An update that solves two vulnerabilities and has one errata is now available.

Description

This update for plasma5-workspace fixes security issues and bugs.

The following vulnerabilities were fixed:

- CVE-2018-6790: Desktop notifications could have been used to load

arbitrary remote images into Plasma, allowing for client IP discovery

(boo#1079429)

- CVE-2018-6791: A specially crafted file system label may have allowed

execution of arbitrary code (boo#1079751)

The following bugs were fixed:

- Plasma could freeze with certain notifications (boo#1013550)

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2018-147=1

To bring your system up-to-date, use "zypper patch".

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64):

drkonqi5-5.8.7-8.1

plasma5-workspace-5.8.7-8.1

plasma5-workspace-devel-5.8.7-8.1

plasma5-workspace-libs-5.8.7-8.1

- SUSE Package Hub for SUSE Linux Enterprise 12 (noarch):

plasma5-workspace-lang-5.8.7-8.1

References

https://www.suse.com/security/cve/CVE-2018-6790.html

https://www.suse.com/security/cve/CVE-2018-6791.html

https://bugzilla.suse.com/1013550

https://bugzilla.suse.com/1079429

https://bugzilla.suse.com/1079751

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0398-1
Rating: important
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here