Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update for kdelibs is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kdelibs security update Advisory ID: RHSA-2020:2833-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2833 Issue date: 2020-07-07 CVE Names: CVE-2019-14744 ==================================================================== 1. Summary: An update for kdelibs is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6) - noarch, x86_64 Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64le, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.6) - noarch, ppc64, s390x Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, ppc64le Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - noarch, s390x 3. Description: The K Desktop Environment (KDE) is a graphical desktop environment for the X Window System. The kdelibs packages include core libraries for the K Desktop Environment. Security Fix(es): * kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744) For more details about the security issue(s), including the impact, a CVSS score,acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The desktop must be restarted (log out, then log back in) for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1740138 - CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6): Source: kdelibs-4.14.8-8.el7_6.src.rpm x86_64: kdelibs-4.14.8-8.el7_6.i686.rpm kdelibs-4.14.8-8.el7_6.x86_64.rpm kdelibs-common-4.14.8-8.el7_6.x86_64.rpm kdelibs-debuginfo-4.14.8-8.el7_6.i686.rpm kdelibs-debuginfo-4.14.8-8.el7_6.x86_64.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.i686.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6): noarch: kdelibs-apidocs-4.14.8-8.el7_6.noarch.rpm x86_64: kdelibs-debuginfo-4.14.8-8.el7_6.i686.rpm kdelibs-debuginfo-4.14.8-8.el7_6.x86_64.rpm kdelibs-devel-4.14.8-8.el7_6.i686.rpm kdelibs-devel-4.14.8-8.el7_6.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.6): Source: kdelibs-4.14.8-8.el7_6.src.rpm ppc64le: kdelibs-4.14.8-8.el7_6.ppc64le.rpm kdelibs-common-4.14.8-8.el7_6.ppc64le.rpm kdelibs-debuginfo-4.14.8-8.el7_6.ppc64le.rpm kdelibs-devel-4.14.8-8.el7_6.ppc64le.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.ppc64le.rpm x86_64: kdelibs-4.14.8-8.el7_6.i686.rpm kdelibs-4.14.8-8.el7_6.x86_64.rpm kdelibs-common-4.14.8-8.el7_6.x86_64.rpm kdelibs-debuginfo-4.14.8-8.el7_6.i686.rpm kdelibs-debuginfo-4.14.8-8.el7_6.x86_64.rpm kdelibs-devel-4.14.8-8.el7_6.i686.rpm kdelibs-devel-4.14.8-8.el7_6.x86_64.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.i686.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v.7): Source: kdelibs-4.14.8-8.el7_6.src.rpm aarch64: kdelibs-4.14.8-8.el7_6.aarch64.rpm kdelibs-common-4.14.8-8.el7_6.aarch64.rpm kdelibs-debuginfo-4.14.8-8.el7_6.aarch64.rpm kdelibs-devel-4.14.8-8.el7_6.aarch64.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.aarch64.rpm ppc64le: kdelibs-4.14.8-8.el7_6.ppc64le.rpm kdelibs-common-4.14.8-8.el7_6.ppc64le.rpm kdelibs-debuginfo-4.14.8-8.el7_6.ppc64le.rpm kdelibs-devel-4.14.8-8.el7_6.ppc64le.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.ppc64le.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.6): Source: kdelibs-4.14.8-8.el7_6.src.rpm noarch: kdelibs-apidocs-4.14.8-8.el7_6.noarch.rpm ppc64: kdelibs-4.14.8-8.el7_6.ppc.rpm kdelibs-4.14.8-8.el7_6.ppc64.rpm kdelibs-common-4.14.8-8.el7_6.ppc64.rpm kdelibs-debuginfo-4.14.8-8.el7_6.ppc.rpm kdelibs-debuginfo-4.14.8-8.el7_6.ppc64.rpm kdelibs-devel-4.14.8-8.el7_6.ppc.rpm kdelibs-devel-4.14.8-8.el7_6.ppc64.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.ppc.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.ppc64.rpm s390x: kdelibs-4.14.8-8.el7_6.s390.rpm kdelibs-4.14.8-8.el7_6.s390x.rpm kdelibs-common-4.14.8-8.el7_6.s390x.rpm kdelibs-debuginfo-4.14.8-8.el7_6.s390.rpm kdelibs-debuginfo-4.14.8-8.el7_6.s390x.rpm kdelibs-devel-4.14.8-8.el7_6.s390.rpm kdelibs-devel-4.14.8-8.el7_6.s390x.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.s390.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.s390x.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7): Source: kdelibs-4.14.8-8.el7_6.src.rpm noarch: kdelibs-apidocs-4.14.8-8.el7_6.noarch.rpm s390x: kdelibs-4.14.8-8.el7_6.s390.rpm kdelibs-4.14.8-8.el7_6.s390x.rpm kdelibs-common-4.14.8-8.el7_6.s390x.rpm kdelibs-debuginfo-4.14.8-8.el7_6.s390.rpm kdelibs-debuginfo-4.14.8-8.el7_6.s390x.rpm kdelibs-devel-4.14.8-8.el7_6.s390.rpm kdelibs-devel-4.14.8-8.el7_6.s390x.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.s390.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.s390x.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-14744 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXwRM2tzjgjWX9erEAQi7Tw//XwPdhGZQX45tJEdek5NAi6Z0EDLXnN55 5pKobv18QhOizrNSeebTnUDBLjk5dQuWnIvl6rpmw0vf+ZfpjkSwUJ95zG7D/os4 nwj8stt0AfGf9VvrxgJnwO/Q3ceJcFqO8NOgxPAvCTD123dUtW41ZEWdWQMSmc/7 lFQOuradvUfR250pYBbkPlcndf6BzOm1DGEdpjtHv8dqL2k4/7V5bQ2y61mdirwf lD2rCsjffofp+j3X4JKf24Oez3cPVEVB52KDYnI+mO+wB+cQsilEkckicy5Rd5fb epuN8sCqaC4wZ9NkRfhWRuRx7P7tA5Fr2/GECZ4HJ0te2wwdH8vVUA3hm4V6U37r SRSl3cRmBM6gIJBRF6UpQQoaOY7AowR9FDlXPmyL1JPuqnzKk9spwWxuJlTEw6rP wLHqrduN3jogAtQsvy6Ums/oEAzkGrdUDtygEMEEU/twV58fxwagFC2Iu4lCvWkg fflweDqS2nQw7X2rOyu54cbSwX/S3vtuwaUkBQkqdwnaXPgpLRPtHYxIocE0sWcP yE5xIJZ4vQ7m0CV1alnoKoiZzaltN0k+Il8t/InCwI9myDzI0z5vQGQzl7sc4AMA 3V3pdD6agZ/r5IznvlmSTaQCtZ8InFhE0ctgvBhacYolbSV4X7qRstTOGHWWllAs bAXkpOCk2UA=Qzee -----END PGP SIGNATURE----- -- RHSA-announce mailing list
kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744). References: - https://bugs.mageia.org/show_bug.cgi?id=25403 . MGASA-2019-0378 - Updated kdelibs4 packages fix security vulnerability Publication date: 13 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0378.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744). References: - https://bugs.mageia.org/show_bug.cgi?id=25403 - https://kde.org/info/security/advisory-20190807-1.txt - https://access.redhat.com/errata/RHSA-2019:2606 - https://www.cve.org/CVERecord?id=CVE-2019-14744 SRPMS: - 7/core/kdelibs4-4.14.38-7.1.mga7 . Mageia releases kdelibs4 update to address a security vulnerability that permits limited user interaction for executing code. Read on for more information.. kdelibs Security Advisory, Mageia Update, Malicious Files Execution, Desktop Application Vulnerability. . LinuxSecurity.com Team
Upstream details at : https://access.redhat.com/errata/RHSA-2019:2606. CentOS Errata and Security Advisory 2019:2606 Important Upstream details at : https://access.redhat.com/errata/RHSA-2019:2606 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 5cb5251df550f50ccb605cf53a6a720f38ac6c7e77ccb34bd7a018a5b8b5ccd0 kdelibs-4.14.8-11.el7_7.i686.rpm 150ca855ef45be0d1f6be00dd7bfed5693743caf8909398ff6e9249c4b33233d kdelibs-4.14.8-11.el7_7.x86_64.rpm eafa49bd4efc99bb5243d022afab94648cca5beb9f05c5d84c2fc4bb0a7b4cc5 kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm 5624f8c9dd40d43e5c7206c0e4bcebdd893a19cc8f292fe8931e92155a053c6b kdelibs-common-4.14.8-11.el7_7.x86_64.rpm d6d94f7b072472531c76e011a8e80db9eaa1efb39b24c9039fb63f68375436c8 kdelibs-devel-4.14.8-11.el7_7.i686.rpm 317a615c096545286367a35d67d64397d541f4b6f1ef8845653851e7231699db kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm 6bdde73688581724d59d663cc615376555bf5c37f6b76bc82d57b24827e31ce5 kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm dc403dcf2ff1ebc81802b80c052bdc166f7f96adf6f5d99ab4a9c9b98e47cffd kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Source: bcdec5a8544827b6196f233b122297ced35c93fd166e848a245bcf39e770212d kdelibs-4.14.8-11.el7_7.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
Important: kdelibs and kde-settings security and bug fix update . Synopsis: Important: kdelibs and kde-settings security and bug fix update Advisory ID: SLSA-2019:2606-1 Issue Date: 2019-09-03 CVE Numbers: CVE-2019-14744 -- * kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744) Bug Fix(es): * kde.csh profile file contains bourne-shell code -- SL7 x86_64 kdelibs-4.14.8-11.el7_7.i686.rpm kdelibs-4.14.8-11.el7_7.x86_64.rpm kdelibs-common-4.14.8-11.el7_7.x86_64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm kdelibs-devel-4.14.8-11.el7_7.i686.rpm kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm noarch kde-settings-19-23.10.el7_7.noarch.rpm kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm qt-settings-19-23.10.el7_7.noarch.rpm kde-settings-minimal-19-23.10.el7_7.noarch.rpm kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm - Scientific Linux Development Team . A significant security patch for kdelibs and kde-settings has been released for Scientific Linux, successfully mitigating a vulnerability that allows for arbitrary code execution.. kdelibs security update, kde-settings bug fix, Scientific Linux advisory. . Severity: Critical. LinuxSecurity.com Team
An update for kdelibs and kde-setting is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kdelibs and kde-settings security and bug fix update Advisory ID: RHSA-2019:2606-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2606 Issue date: 2019-09-03 CVE Names: CVE-2019-14744 ==================================================================== 1. Summary: An update for kdelibs and kde-setting is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, s390x Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch 3. Description: The K Desktop Environment (KDE) is a graphical desktop environment for the X Window System. The kdelibs packages include core libraries for the K Desktop Environment. Security Fix(es): * kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744) For more details about thesecurity issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * kde.csh profile file contains bourne-shell code (BZ#1740042) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The desktop must be restarted (log out, then log back in) for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1740042 - kde.csh profile file contains bourne-shell code [rhel-7.7.z] 1740138 - CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: kde-settings-19-23.10.el7_7.src.rpm kdelibs-4.14.8-11.el7_7.src.rpm noarch: kde-settings-19-23.10.el7_7.noarch.rpm kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm qt-settings-19-23.10.el7_7.noarch.rpm x86_64: kdelibs-4.14.8-11.el7_7.i686.rpm kdelibs-4.14.8-11.el7_7.x86_64.rpm kdelibs-common-4.14.8-11.el7_7.x86_64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): noarch: kde-settings-minimal-19-23.10.el7_7.noarch.rpm kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm x86_64: kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-devel-4.14.8-11.el7_7.i686.rpm kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v.7): Source: kde-settings-19-23.10.el7_7.src.rpm kdelibs-4.14.8-11.el7_7.src.rpm noarch: kde-settings-19-23.10.el7_7.noarch.rpm qt-settings-19-23.10.el7_7.noarch.rpm x86_64: kdelibs-4.14.8-11.el7_7.i686.rpm kdelibs-4.14.8-11.el7_7.x86_64.rpm kdelibs-common-4.14.8-11.el7_7.x86_64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): noarch: kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-minimal-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm x86_64: kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-devel-4.14.8-11.el7_7.i686.rpm kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: kde-settings-19-23.10.el7_7.src.rpm kdelibs-4.14.8-11.el7_7.src.rpm noarch: kde-settings-19-23.10.el7_7.noarch.rpm kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm qt-settings-19-23.10.el7_7.noarch.rpm ppc64le: kdelibs-4.14.8-11.el7_7.ppc64le.rpm kdelibs-common-4.14.8-11.el7_7.ppc64le.rpm kdelibs-debuginfo-4.14.8-11.el7_7.ppc64le.rpm kdelibs-devel-4.14.8-11.el7_7.ppc64le.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.ppc64le.rpm x86_64: kdelibs-4.14.8-11.el7_7.i686.rpm kdelibs-4.14.8-11.el7_7.x86_64.rpm kdelibs-common-4.14.8-11.el7_7.x86_64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-devel-4.14.8-11.el7_7.i686.rpm kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): Source: kdelibs-4.14.8-11.el7_7.src.rpm noarch: kde-settings-19-23.10.el7_7.noarch.rpm kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-minimal-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm ppc64: kdelibs-4.14.8-11.el7_7.ppc.rpm kdelibs-4.14.8-11.el7_7.ppc64.rpm kdelibs-common-4.14.8-11.el7_7.ppc64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.ppc.rpm kdelibs-debuginfo-4.14.8-11.el7_7.ppc64.rpm kdelibs-devel-4.14.8-11.el7_7.ppc.rpm kdelibs-devel-4.14.8-11.el7_7.ppc64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.ppc.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.ppc64.rpm s390x: kdelibs-4.14.8-11.el7_7.s390.rpm kdelibs-4.14.8-11.el7_7.s390x.rpm kdelibs-common-4.14.8-11.el7_7.s390x.rpm kdelibs-debuginfo-4.14.8-11.el7_7.s390.rpm kdelibs-debuginfo-4.14.8-11.el7_7.s390x.rpm kdelibs-devel-4.14.8-11.el7_7.s390.rpm kdelibs-devel-4.14.8-11.el7_7.s390x.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.s390.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.s390x.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: kde-settings-19-23.10.el7_7.src.rpm kdelibs-4.14.8-11.el7_7.src.rpm noarch: kde-settings-19-23.10.el7_7.noarch.rpm kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm qt-settings-19-23.10.el7_7.noarch.rpm x86_64: kdelibs-4.14.8-11.el7_7.i686.rpm kdelibs-4.14.8-11.el7_7.x86_64.rpm kdelibs-common-4.14.8-11.el7_7.x86_64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-devel-4.14.8-11.el7_7.i686.rpm kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): noarch: kde-settings-minimal-19-23.10.el7_7.noarch.rpm kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verifythe signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-14744 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXW6mb9zjgjWX9erEAQiw0RAAhNN2C/nEIChc7w6wakv+TRHxmENmhjJH mmEupc5Hei3bSCPYBBLKn9+J3pv9eN6l3YREFml/cdssoMMP74Op3U/8i8mDYH2R ONXhA5Eh1eTUqe4v+kmFSn2GHy4t6SEipgXFkybLhZsCrek7R8ieoR1JM4z83LOv ijMHoZL4ChuS8He5A+g99PGya/kpizFSDzBD2R2the8aYybQ/7n3eNJ7zWHj6aR7 dJCQm13yBUiuEUOTnkn+0MQMIGQEE1PYmk5AKUztXfvip6trsRV2Ypnri8ds6/qj QuBCfJQqlyKlXbXoLhg4IB3yKeuCQ42OnLo2bciJvQi0ayicrHCciV7qoWCDl9Ff ViLoGUA4twNr88yRRIGdGJKMnCB+onm+ZT9w77SaVpRIXX/VjSXbh78x85x4+9wf M8gNhcTAicTTkHfAv3VKGwXbhMaZq7bvDpNpxtsm+Qi8mYgQ0DnwgBSCUH7gwARP XTeauIKoonztvjFLSeOIroPZdw7JjZ25FI57EUE9pkIyL+Jf3O2gNI23rJ+Ogo/J 0HGExkRSPcrfED/lqGVTPuYboWofelxPwX1m8B2zGyXfSShlFlX65siAt7ELkY25 DzkFpd0w7VRF2Rug+ZjwooXKUDglb6nXWbTY+hHCdttc93ildGkCA6tBNbIVGzXM 180wxDMpjJw=gSSD -----END PGP SIGNATURE----- -- RHSA-announce mailing list
This update fixes **CVE-2019-14744 (kconfig arbitrary shell code execution)** in the KDE 3 compatibility version of kdelibs used by legacy KDE 3 applications. The full list of fixes in this `kdelibs3` build: * fixes **CVE-2019-14744** - `kconfig`: malicious `.desktop` files (and others) would execute code. KConfig had a well-meaning feature that allowed configuration files to execute arbitrary. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-9f2ee52c88 2019-08-19 02:28:49.021905 --------------------------------------------------------------------------------Name : kdelibs3 Product : Fedora 29 Version : 3.5.10 Release : 101.fc29 URL : https://kde.org/ Summary : KDE 3 Libraries Description : Libraries for KDE 3: KDE Libraries included: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation). --------------------------------------------------------------------------------Update Information: This update fixes **CVE-2019-14744 (kconfig arbitrary shell code execution)** in the KDE 3 compatibility version of kdelibs used by legacy KDE 3 applications. The full list of fixes in this `kdelibs3` build: * fixes **CVE-2019-14744** -`kconfig`: malicious `.desktop` files (and others) would execute code. KConfig had a well-meaning feature that allowed configuration files to execute arbitrary shell commands. Unfortunately, this could be abused by untrusted `.desktop` files to execute arbitrary code as the target user, without the user even running the `.desktop` file. Therefore, this update removes that ill-fated feature. (Backported by Kevin Kofler from upstream: `kf5-kconfig` fix by David Faure, `kdelibs` 4 backport by Kai Uwe Broulik.) * adds native support for **xdg-user-dirs** for *Desktop* and *Documents*, without shelling outto `xdg-user-dir` from the config file. This is needed due to the above security fix. (This feature was previously implemented in the Fedora `kde-settings` by shelling out to `xdg-user-dir` from the config file using the KConfig feature removed above.) (Backported by Kevin Kofler from Trinity Desktop / Timothy Pearson.) * fixes a **KJS double-free** that could crash legacy KDE 3 applications such as Quanta Plus when trying to execute JavaScript. (Backported by OpenSUSE / Wolfgang Bauer from Trinity Desktop / Timothy Pearson.) --------------------------------------------------------------------------------ChangeLog: * Sat Aug 10 2019 Kevin Kofler - 3.5.10-101 - Backport CVE-2019-14744 fix by David Faure and Kai Uwe Broulik from kdelibs 4 - Backport native xdg-user-dirs support by Timothy Pearson from Trinity (needed to fix the regression that would otherwise result from the above security fix) - Backport KJS double-free fix by Timothy Pearson (backport by wbauer/OpenSUSE) * Thu Jul 25 2019 Fedora Release Engineering - 3.5.10-100 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Thu Apr 11 2019 Richard Shaw - 3.5.10-99 - Rebuild for OpenEXR 2.3.0. * Fri Feb 1 2019 Fedora Release Engineering - 3.5.10-98 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Sat Jan 5 2019 Kevin Kofler - 3.5.10-97 - Rebuild for the new hardcoded qt3 build key in Rawhide - Fix aarch64 FTBFS due to libtool not liking the file output on *.so files --------------------------------------------------------------------------------References: [ 1 ] Bug #1740138 - CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction https://bugzilla.redhat.com/show_bug.cgi?id=1740138 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-9f2ee52c88' at the command line.For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
New kdelibs packages are available for Slackware 14.2 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] kdelibs (SSA:2019-220-01) New kdelibs packages are available for Slackware 14.2 and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/kdelibs-4.14.38-i586-1_slack14.2.txz: Upgraded. kconfig: malicious .desktop files (and others) would execute code. For more information, see: https://mail.kde.org/pipermail/kde-announce/2019-August/000047.html https://www.cve.org/CVERecord?id=CVE-2019-14744 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.2 package: bf9cdc634d392f7c05561a7ddc298388 kdelibs-4.14.38-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 3646da04eed2835db47afb3bab02c78b kdelibs-4.14.38-x86_64-1_slack14.2.txz Slackware -current package: a88a3859f1f7fb57df6579ba45153e80 kde/kdelibs-4.14.38-i586-4.txz Slackware x86_64 -current package: cb52242ec03ff9430894b1d7aee206cf kde/kdelibs-4.14.38-x86_64-4.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg kdelibs-4.14.38-i586-1_slack14.2.txz +-----+ . Updated kdelibs packages for Slackware 14.2 and current address a serious security flaw that affects users.. Kdelibs Update, Slackware Security, Package Upgrade, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team
Upstream details at : https://access.redhat.com/errata/RHSA-2017:1264.html. CentOS Errata and Security Advisory 2017:1264 Important Upstream details at : https://access.redhat.com/errata/RHSA-2017:1264.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: f3e22666fba8c8111928a8f24136d3c9264c9ff493a7ed9e835a6bf5d7ce7140 kdelibs-4.14.8-6.el7_3.i686.rpm 94f689579faf8da4d7ad45123bb2c06bc11489165fef94b6147f51d31bcb30e8 kdelibs-4.14.8-6.el7_3.x86_64.rpm f7b0fc9c737d4b1bde539fe0ad6244197f2f33394af0681cfcf57140b5298b2a kdelibs-apidocs-4.14.8-6.el7_3.noarch.rpm 954c2ecab2f8bb2366f3b1877650dde9756c351b9a05143c9bde1d932decb191 kdelibs-common-4.14.8-6.el7_3.x86_64.rpm 873ec7107fc9f785552ed6364cab5177843b68eee619ddb23581980fcca75cc2 kdelibs-devel-4.14.8-6.el7_3.i686.rpm 8ba9a2644e75f5e404f6a41070fa4954e9e309ecc8e1fd6342b56cdc307c877c kdelibs-devel-4.14.8-6.el7_3.x86_64.rpm 0119fe8e7df71838bf35a67f96888e310b7f25f8c86282acf8474b03ae7326d5 kdelibs-ktexteditor-4.14.8-6.el7_3.i686.rpm 64978ded4630c6f325b78170824280d86bf2a1566232b9e8e5025992162ab858 kdelibs-ktexteditor-4.14.8-6.el7_3.x86_64.rpm Source: c2931314523bca3fb71d17d9da6bc61d118021c46ac3f70c7f4290b0b000900c kdelibs-4.14.8-6.el7_3.src.rpm -- Johnny Hughes CentOS Project { http://www.centos.org/ } irc: hughesjr, #
Get the latest Linux and open source security news straight to your inbox.