Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE: 2019:1851-2 Important: Kconfig Command Execution Severity

opensuse
Calendar Grey August 14, 2019
Dist Opensuse Esm H88
The latest openSUSE release resolves a critical bug affecting kconfig and kdelibs4, thereby enhancing overall system reliability.
An update that fixes one vulnerability is now available.

Description

This update for kconfig, kdelibs4 fixes the following issues:

- CVE-2019-14744: Fixed a command execution by an shell expansion

(boo#1144600).

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2019-1851=1

Package List

- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):

kconf_update5-5.55.0-bp151.3.5.1

kconf_update5-debuginfo-5.55.0-bp151.3.5.1

kconfig-debugsource-5.55.0-bp151.3.5.1

kconfig-devel-5.55.0-bp151.3.5.1

kconfig-devel-debuginfo-5.55.0-bp151.3.5.1

kdelibs4-4.14.38-bp151.9.5.1

kdelibs4-branding-upstream-4.14.38-bp151.9.5.1

kdelibs4-core-4.14.38-bp151.9.5.1

kdelibs4-core-debuginfo-4.14.38-bp151.9.5.1

kdelibs4-debuginfo-4.14.38-bp151.9.5.1

kdelibs4-debugsource-4.14.38-bp151.9.5.1

kdelibs4-doc-4.14.38-bp151.9.5.1

kdelibs4-doc-debuginfo-4.14.38-bp151.9.5.1

libKF5ConfigCore5-5.55.0-bp151.3.5.1

libKF5ConfigCore5-debuginfo-5.55.0-bp151.3.5.1

libKF5ConfigGui5-5.55.0-bp151.3.5.1

libKF5ConfigGui5-debuginfo-5.55.0-bp151.3.5.1

libkde4-4.14.38-bp151.9.5.1

libkde4-debuginfo-4.14.38-bp151.9.5.1

libkde4-devel-4.14.38-bp151.9.5.1

libkde4-devel-debuginfo-4.14.38-bp151.9.5.1

libkdecore4-4.14.38-bp151.9.5.1

libkdecore4-debuginfo-4.14.38-bp151.9.5.1

libkdecore4-devel-4.14.38-bp151.9.5.1

libkdecore4-devel-debuginfo-4.14.38-bp...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2019-14744.html

https://bugzilla.suse.com/1144600

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:1851-2
Rating: important
Affected Products: openSUSE Backports SLE-15-SP1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here