Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE: 2019:1851-1 Important: kconfig Command Execution Threat

opensuse
Calendar Grey August 13, 2019
Dist Opensuse Esm H88
The recent update for kconfig and kdelibs4 resolves a significant command execution vulnerability in openSUSE.
An update that fixes one vulnerability is now available.

Description

This update for kconfig, kdelibs4 fixes the following issues:

- CVE-2019-14744: Fixed a command execution by an shell expansion

(boo#1144600).

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2019-1851=1

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64):

kconf_update5-5.20.0-8.1

kconf_update5-5.26.0-8.1

kconf_update5-5.32.0-7.1

kconf_update5-debuginfo-5.20.0-8.1

kconf_update5-debuginfo-5.26.0-8.1

kconf_update5-debuginfo-5.32.0-7.1

kconfig-debugsource-5.20.0-8.1

kconfig-debugsource-5.26.0-8.1

kconfig-debugsource-5.32.0-7.1

kconfig-devel-5.20.0-8.1

kconfig-devel-5.26.0-8.1

kconfig-devel-5.32.0-7.1

kconfig-devel-debuginfo-5.20.0-8.1

kconfig-devel-debuginfo-5.26.0-8.1

kconfig-devel-debuginfo-5.32.0-7.1

kdelibs4-4.14.18-14.1

kdelibs4-4.14.25-13.1

kdelibs4-4.14.33-7.2

kdelibs4-branding-upstream-4.14.18-14.1

kdelibs4-branding-upstream-4.14.25-13.1

kdelibs4-branding-upstream-4.14.33-7.2

kdelibs4-core-4.14.18-14.1

kdelibs4-core-4.14.25-13.1

kdelibs4-core-4.14.33-7.2

kdelibs4-core-debuginfo-4.14.18-14.1

kdelibs4-core-debuginfo-4.14.25-13.1

kdelibs4-core-debuginfo-4.14.33-7.2

kdelibs4-debuginfo-4.14.18-14.1

kdelibs4-debuginfo-4.14.25-13.1

kdelibs4-debuginfo-4.14.33-7.2

kdelibs4-debugsource-4.14.18-...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2019-14744.html

https://bugzilla.suse.com/1144600

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:1851-1
Rating: important
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here