Dominik Penner discovered a flaw in how KConfig interpreted shell commands in desktop files and other configuration files. An attacker may trick users into installing specially crafted files which could then be used to execute arbitrary code, e.g. a file manager trying to find out . Package : kde4libs Version : 4:4.14.2-5+deb8u3 CVE ID : CVE-2019-14744 Debian Bug : 934268 Dominik Penner discovered a flaw in how KConfig interpreted shell commands in desktop files and other configuration files. An attacker may trick users into installing specially crafted files which could then be used to execute arbitrary code, e.g. a file manager trying to find out the icon for a file or any application using KConfig. Thus the entire feature of supporting shell commands in KConfig entries has been removed. For Debian 8 "Jessie", this problem has been fixed in version 4:4.14.2-5+deb8u3. We recommend that you upgrade your kde4libs packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . CVE-2021-31529 affects libgtk in Ubuntu 20.04. Update promptly to protect against potential remote code execution vulnerabilities.. kde4libs Security Update, Debian 8 Update, Shell Command Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities were discovered in kde4libs, the core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: . Hash: SHA256 Package : kde4libs Version : 4:4.8.4-4+deb7u3 CVE ID : CVE-2013-2074 CVE-2017-6410 CVE-2017-8422 Debian Bug : 856890 Several vulnerabilities were discovered in kde4libs, the core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2017-6410 Itzik Kotler, Yonatan Fridburg and Amit Klein of Safebreach Labs reported that URLs are not sanitized before passing them to FindProxyForURL, potentially allowing a remote attacker to obtain sensitive information via a crafted PAC file. CVE-2017-8422 Sebastian Krahmer from SUSE discovered that the KAuth framework contains a logic flaw in which the service invoking dbus is not properly checked. This flaw allows spoofing the identity of the caller and gaining root privileges from an unprivileged account. CVE-2013-2074 It was discovered that KIO would show web authentication credentials in some error cases. For Debian 7 "Wheezy", these problems have been fixed in version 4:4.8.4-4+deb7u3. We recommend that you upgrade your kde4libs packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Urgent KDE4 libraries security patch tackles various threats on Debian Wheezy. Safeguard your system immediately!. Debian Security,kde4libs Update,Privilege Escalation,Security Fixes. . Severity: Important. LinuxSecurity.com Team
Several vulnerabilities were discovered in kde4libs, the core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3849-1
Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly handle the extraction of archives with "../" in the file paths. A remote attacker can take advantage of this flaw to overwrite files outside of the . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3643-1
KDE-Libs could be made to overwrite files.. =========================================================================Ubuntu Security Notice USN-3042-1 July 26, 2016 kde4libs vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: KDE-Libs could be made to overwrite files. Software Description: - kde4libs: KDE 4 core applications and libraries Details: Andreas Cord-Landwehr discovered that KDE-Libs incorrectly handled extracting certain archives. If a user were tricked into extracting a specially-crafted archive, a remote attacker could use this issue to overwrite arbitrary files out of the extraction directory. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: libkdecore5 4:4.14.13-0ubuntu1.1 Ubuntu 14.04 LTS: libkdecore5 4:4.13.3-0ubuntu0.3 Ubuntu 12.04 LTS: libkdecore5 4:4.8.5-0ubuntu0.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3042-1 CVE-2016-6232 Package Information: https://launchpad.net/ubuntu/+source/kde4libs/4:4.14.13-0ubuntu1.1 https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.3-0ubuntu0.3 https://launchpad.net/ubuntu/+source/kde4libs/4:4.8.5-0ubuntu0.5 . KDE Libraries in Ubuntu may permit unauthorized users to alter files. Security patch required for mitigation. Discover more details here.. KDE-Libs Vulnerability, Ubuntu Security Notice, Archive Security Issue. . Severity: Critical. LinuxSecurity.com Team
Sebastian Krahmer discovered that Kauth used Policykit insecurely by relying on the process ID. This could result in privilege escalation. For the stable distribution (wheezy), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3004-1
Several security issues have been discovered in kde4libs, core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1868-1
Get the latest Linux and open source security news straight to your inbox.