Security fix for CVE-2019-14822. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-b577187ba8 2019-09-25 01:06:52.995907 --------------------------------------------------------------------------------Name : ibus Product : Fedora 30 Version : 1.5.20 Release : 5.fc30 URL : https://github.com/ibus/ibus/wiki Summary : Intelligent Input Bus for Linux OS Description : IBus means Intelligent Input Bus. It is an input framework for Linux OS. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-14822 --------------------------------------------------------------------------------ChangeLog: * Fri Sep 13 2019 Takao Fujiwara - 1.5.20-5 - Fix #1751940 - CVE-2019-14822 GDBusServer peer authorization * Mon May 13 2019 Takao Fujiwara - 1.5.20-4 - Keep preedit cursor_pos and visible in clearing preedit text for Hangul * Tue Apr 23 2019 Takao Fujiwara - 1.5.20-3 - Fix i18n ibus-setup - Provide ibus.its * Tue Apr 16 2019 Takao Fujiwara - 1.5.20-2 - Rebuilt for unicode-ucd- 12.0.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1717958 - CVE-2019-14822 ibus: missing authorization allows local attacker to access the input bus of another user https://bugzilla.redhat.com/show_bug.cgi?id=1717958 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-b577187ba8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Simon McVittie reported a flaw in ibus, the Intelligent Input Bus. Due to a misconfiguration during the setup of the DBus, any unprivileged user could monitor and send method calls to the ibus bus of another user, if able to discover the UNIX socket used by another user connected . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4525-1
Get the latest Linux and open source security news straight to your inbox.