=========================================================================Ubuntu Security Notice USN-6035-1
April 20, 2023

kauth vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 ESM
- Ubuntu 16.04 ESM

Summary:

KAuth could be made to crash or run programs if it received specially crafted
input.

Software Description:
- kauth: Abstraction to system policy and authentication features

Details:

It was discovered that KAuth incorrectly handled some configuration parameterswith specially crafted arbitrary types. An attacker could possibly use this
issue to cause a denial of service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 ESM:
  libkf5auth-data                 5.44.0-0ubuntu1+esm1
  libkf5auth5                     5.44.0-0ubuntu1+esm1

Ubuntu 16.04 ESM:
  libkf5auth-data                 5.18.0-0ubuntu2+esm1
  libkf5auth5                     5.18.0-0ubuntu2+esm1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-6035-1
  CVE-2019-7443

Ubuntu 6035-1: KAuth vulnerability

April 20, 2023
KAuth could be made to crash or run programs if it received specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 ESM: libkf5auth-data 5.44.0-0ubuntu1+esm1 libkf5auth5 5.44.0-0ubuntu1+esm1 Ubuntu 16.04 ESM: libkf5auth-data 5.18.0-0ubuntu2+esm1 libkf5auth5 5.18.0-0ubuntu2+esm1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6035-1

CVE-2019-7443

Severity
April 20, 2023

Package Information

Related News