Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 90 articles for you...
98

Red Hat: RHSA-2020-2833-01 Important: kdelibs Code Execution Risk

An update for kdelibs is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kdelibs security update Advisory ID: RHSA-2020:2833-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2833 Issue date: 2020-07-07 CVE Names: CVE-2019-14744 ==================================================================== 1. Summary: An update for kdelibs is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6) - noarch, x86_64 Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64le, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.6) - noarch, ppc64, s390x Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, ppc64le Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - noarch, s390x 3. Description: The K Desktop Environment (KDE) is a graphical desktop environment for the X Window System. The kdelibs packages include core libraries for the K Desktop Environment. Security Fix(es): * kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744) For more details about the security issue(s), including the impact, a CVSS score,acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The desktop must be restarted (log out, then log back in) for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1740138 - CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6): Source: kdelibs-4.14.8-8.el7_6.src.rpm x86_64: kdelibs-4.14.8-8.el7_6.i686.rpm kdelibs-4.14.8-8.el7_6.x86_64.rpm kdelibs-common-4.14.8-8.el7_6.x86_64.rpm kdelibs-debuginfo-4.14.8-8.el7_6.i686.rpm kdelibs-debuginfo-4.14.8-8.el7_6.x86_64.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.i686.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6): noarch: kdelibs-apidocs-4.14.8-8.el7_6.noarch.rpm x86_64: kdelibs-debuginfo-4.14.8-8.el7_6.i686.rpm kdelibs-debuginfo-4.14.8-8.el7_6.x86_64.rpm kdelibs-devel-4.14.8-8.el7_6.i686.rpm kdelibs-devel-4.14.8-8.el7_6.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.6): Source: kdelibs-4.14.8-8.el7_6.src.rpm ppc64le: kdelibs-4.14.8-8.el7_6.ppc64le.rpm kdelibs-common-4.14.8-8.el7_6.ppc64le.rpm kdelibs-debuginfo-4.14.8-8.el7_6.ppc64le.rpm kdelibs-devel-4.14.8-8.el7_6.ppc64le.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.ppc64le.rpm x86_64: kdelibs-4.14.8-8.el7_6.i686.rpm kdelibs-4.14.8-8.el7_6.x86_64.rpm kdelibs-common-4.14.8-8.el7_6.x86_64.rpm kdelibs-debuginfo-4.14.8-8.el7_6.i686.rpm kdelibs-debuginfo-4.14.8-8.el7_6.x86_64.rpm kdelibs-devel-4.14.8-8.el7_6.i686.rpm kdelibs-devel-4.14.8-8.el7_6.x86_64.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.i686.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v.7): Source: kdelibs-4.14.8-8.el7_6.src.rpm aarch64: kdelibs-4.14.8-8.el7_6.aarch64.rpm kdelibs-common-4.14.8-8.el7_6.aarch64.rpm kdelibs-debuginfo-4.14.8-8.el7_6.aarch64.rpm kdelibs-devel-4.14.8-8.el7_6.aarch64.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.aarch64.rpm ppc64le: kdelibs-4.14.8-8.el7_6.ppc64le.rpm kdelibs-common-4.14.8-8.el7_6.ppc64le.rpm kdelibs-debuginfo-4.14.8-8.el7_6.ppc64le.rpm kdelibs-devel-4.14.8-8.el7_6.ppc64le.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.ppc64le.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.6): Source: kdelibs-4.14.8-8.el7_6.src.rpm noarch: kdelibs-apidocs-4.14.8-8.el7_6.noarch.rpm ppc64: kdelibs-4.14.8-8.el7_6.ppc.rpm kdelibs-4.14.8-8.el7_6.ppc64.rpm kdelibs-common-4.14.8-8.el7_6.ppc64.rpm kdelibs-debuginfo-4.14.8-8.el7_6.ppc.rpm kdelibs-debuginfo-4.14.8-8.el7_6.ppc64.rpm kdelibs-devel-4.14.8-8.el7_6.ppc.rpm kdelibs-devel-4.14.8-8.el7_6.ppc64.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.ppc.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.ppc64.rpm s390x: kdelibs-4.14.8-8.el7_6.s390.rpm kdelibs-4.14.8-8.el7_6.s390x.rpm kdelibs-common-4.14.8-8.el7_6.s390x.rpm kdelibs-debuginfo-4.14.8-8.el7_6.s390.rpm kdelibs-debuginfo-4.14.8-8.el7_6.s390x.rpm kdelibs-devel-4.14.8-8.el7_6.s390.rpm kdelibs-devel-4.14.8-8.el7_6.s390x.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.s390.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.s390x.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7): Source: kdelibs-4.14.8-8.el7_6.src.rpm noarch: kdelibs-apidocs-4.14.8-8.el7_6.noarch.rpm s390x: kdelibs-4.14.8-8.el7_6.s390.rpm kdelibs-4.14.8-8.el7_6.s390x.rpm kdelibs-common-4.14.8-8.el7_6.s390x.rpm kdelibs-debuginfo-4.14.8-8.el7_6.s390.rpm kdelibs-debuginfo-4.14.8-8.el7_6.s390x.rpm kdelibs-devel-4.14.8-8.el7_6.s390.rpm kdelibs-devel-4.14.8-8.el7_6.s390x.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.s390.rpm kdelibs-ktexteditor-4.14.8-8.el7_6.s390x.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-14744 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXwRM2tzjgjWX9erEAQi7Tw//XwPdhGZQX45tJEdek5NAi6Z0EDLXnN55 5pKobv18QhOizrNSeebTnUDBLjk5dQuWnIvl6rpmw0vf+ZfpjkSwUJ95zG7D/os4 nwj8stt0AfGf9VvrxgJnwO/Q3ceJcFqO8NOgxPAvCTD123dUtW41ZEWdWQMSmc/7 lFQOuradvUfR250pYBbkPlcndf6BzOm1DGEdpjtHv8dqL2k4/7V5bQ2y61mdirwf lD2rCsjffofp+j3X4JKf24Oez3cPVEVB52KDYnI+mO+wB+cQsilEkckicy5Rd5fb epuN8sCqaC4wZ9NkRfhWRuRx7P7tA5Fr2/GECZ4HJ0te2wwdH8vVUA3hm4V6U37r SRSl3cRmBM6gIJBRF6UpQQoaOY7AowR9FDlXPmyL1JPuqnzKk9spwWxuJlTEw6rP wLHqrduN3jogAtQsvy6Ums/oEAzkGrdUDtygEMEEU/twV58fxwagFC2Iu4lCvWkg fflweDqS2nQw7X2rOyu54cbSwX/S3vtuwaUkBQkqdwnaXPgpLRPtHYxIocE0sWcP yE5xIJZ4vQ7m0CV1alnoKoiZzaltN0k+Il8t/InCwI9myDzI0z5vQGQzl7sc4AMA 3V3pdD6agZ/r5IznvlmSTaQCtZ8InFhE0ctgvBhacYolbSV4X7qRstTOGHWWllAs bAXkpOCk2UA=Qzee -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . KDE kdelibs patch for Fedora distributions resolves a significant vulnerability that permits code execution upon user engagement.. kdelibs Update, Red Hat Security, Important Advisory, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 07, 2020 Important Red Hat
203

Mageia: 2020-0451 Moderate: libjpeg Code Exploitation Threat

kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744). References: - https://bugs.mageia.org/show_bug.cgi?id=25403 . MGASA-2019-0378 - Updated kdelibs4 packages fix security vulnerability Publication date: 13 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0378.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744). References: - https://bugs.mageia.org/show_bug.cgi?id=25403 - https://kde.org/info/security/advisory-20190807-1.txt - https://access.redhat.com/errata/RHSA-2019:2606 - https://www.cve.org/CVERecord?id=CVE-2019-14744 SRPMS: - 7/core/kdelibs4-4.14.38-7.1.mga7 . Mageia releases kdelibs4 update to address a security vulnerability that permits limited user interaction for executing code. Read on for more information.. kdelibs Security Advisory, Mageia Update, Malicious Files Execution, Desktop Application Vulnerability. . LinuxSecurity.com Team

Calendar%202 Dec 13, 2019 Mageia
199

CentOS 7: CESA-2019-2606 Important Kdelibs DoS Advisory

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2606. CentOS Errata and Security Advisory 2019:2606 Important Upstream details at : https://access.redhat.com/errata/RHSA-2019:2606 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 5cb5251df550f50ccb605cf53a6a720f38ac6c7e77ccb34bd7a018a5b8b5ccd0 kdelibs-4.14.8-11.el7_7.i686.rpm 150ca855ef45be0d1f6be00dd7bfed5693743caf8909398ff6e9249c4b33233d kdelibs-4.14.8-11.el7_7.x86_64.rpm eafa49bd4efc99bb5243d022afab94648cca5beb9f05c5d84c2fc4bb0a7b4cc5 kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm 5624f8c9dd40d43e5c7206c0e4bcebdd893a19cc8f292fe8931e92155a053c6b kdelibs-common-4.14.8-11.el7_7.x86_64.rpm d6d94f7b072472531c76e011a8e80db9eaa1efb39b24c9039fb63f68375436c8 kdelibs-devel-4.14.8-11.el7_7.i686.rpm 317a615c096545286367a35d67d64397d541f4b6f1ef8845653851e7231699db kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm 6bdde73688581724d59d663cc615376555bf5c37f6b76bc82d57b24827e31ce5 kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm dc403dcf2ff1ebc81802b80c052bdc166f7f96adf6f5d99ab4a9c9b98e47cffd kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Source: bcdec5a8544827b6196f233b122297ced35c93fd166e848a245bcf39e770212d kdelibs-4.14.8-11.el7_7.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent CentOS 7 Kdelibs Security Advisory CESA-2019-2606 highlights significant vulnerabilities within key kdelibs components, which are now rectified.. CentOS 7 Security, Kdelibs Update, CentOS Errata, Security Advisory, Important Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 18, 2019 Important CentOS
200

Scientific Linux 7: SLSA-2019-2606-1 Critical: kdelibs Code Execution Risk

Important: kdelibs and kde-settings security and bug fix update . Synopsis: Important: kdelibs and kde-settings security and bug fix update Advisory ID: SLSA-2019:2606-1 Issue Date: 2019-09-03 CVE Numbers: CVE-2019-14744 -- * kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744) Bug Fix(es): * kde.csh profile file contains bourne-shell code -- SL7 x86_64 kdelibs-4.14.8-11.el7_7.i686.rpm kdelibs-4.14.8-11.el7_7.x86_64.rpm kdelibs-common-4.14.8-11.el7_7.x86_64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm kdelibs-devel-4.14.8-11.el7_7.i686.rpm kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm noarch kde-settings-19-23.10.el7_7.noarch.rpm kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm qt-settings-19-23.10.el7_7.noarch.rpm kde-settings-minimal-19-23.10.el7_7.noarch.rpm kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm - Scientific Linux Development Team . A significant security patch for kdelibs and kde-settings has been released for Scientific Linux, successfully mitigating a vulnerability that allows for arbitrary code execution.. kdelibs security update, kde-settings bug fix, Scientific Linux advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 03, 2019 Critical Scientific Linux
98

Critical Risk of Code Execution in kdelibs for Red Hat Enterprise Linux 7

An update for kdelibs and kde-setting is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kdelibs and kde-settings security and bug fix update Advisory ID: RHSA-2019:2606-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2606 Issue date: 2019-09-03 CVE Names: CVE-2019-14744 ==================================================================== 1. Summary: An update for kdelibs and kde-setting is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, s390x Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch 3. Description: The K Desktop Environment (KDE) is a graphical desktop environment for the X Window System. The kdelibs packages include core libraries for the K Desktop Environment. Security Fix(es): * kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744) For more details about thesecurity issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * kde.csh profile file contains bourne-shell code (BZ#1740042) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The desktop must be restarted (log out, then log back in) for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1740042 - kde.csh profile file contains bourne-shell code [rhel-7.7.z] 1740138 - CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: kde-settings-19-23.10.el7_7.src.rpm kdelibs-4.14.8-11.el7_7.src.rpm noarch: kde-settings-19-23.10.el7_7.noarch.rpm kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm qt-settings-19-23.10.el7_7.noarch.rpm x86_64: kdelibs-4.14.8-11.el7_7.i686.rpm kdelibs-4.14.8-11.el7_7.x86_64.rpm kdelibs-common-4.14.8-11.el7_7.x86_64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): noarch: kde-settings-minimal-19-23.10.el7_7.noarch.rpm kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm x86_64: kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-devel-4.14.8-11.el7_7.i686.rpm kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v.7): Source: kde-settings-19-23.10.el7_7.src.rpm kdelibs-4.14.8-11.el7_7.src.rpm noarch: kde-settings-19-23.10.el7_7.noarch.rpm qt-settings-19-23.10.el7_7.noarch.rpm x86_64: kdelibs-4.14.8-11.el7_7.i686.rpm kdelibs-4.14.8-11.el7_7.x86_64.rpm kdelibs-common-4.14.8-11.el7_7.x86_64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): noarch: kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-minimal-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm x86_64: kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-devel-4.14.8-11.el7_7.i686.rpm kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: kde-settings-19-23.10.el7_7.src.rpm kdelibs-4.14.8-11.el7_7.src.rpm noarch: kde-settings-19-23.10.el7_7.noarch.rpm kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm qt-settings-19-23.10.el7_7.noarch.rpm ppc64le: kdelibs-4.14.8-11.el7_7.ppc64le.rpm kdelibs-common-4.14.8-11.el7_7.ppc64le.rpm kdelibs-debuginfo-4.14.8-11.el7_7.ppc64le.rpm kdelibs-devel-4.14.8-11.el7_7.ppc64le.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.ppc64le.rpm x86_64: kdelibs-4.14.8-11.el7_7.i686.rpm kdelibs-4.14.8-11.el7_7.x86_64.rpm kdelibs-common-4.14.8-11.el7_7.x86_64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-devel-4.14.8-11.el7_7.i686.rpm kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): Source: kdelibs-4.14.8-11.el7_7.src.rpm noarch: kde-settings-19-23.10.el7_7.noarch.rpm kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-minimal-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm ppc64: kdelibs-4.14.8-11.el7_7.ppc.rpm kdelibs-4.14.8-11.el7_7.ppc64.rpm kdelibs-common-4.14.8-11.el7_7.ppc64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.ppc.rpm kdelibs-debuginfo-4.14.8-11.el7_7.ppc64.rpm kdelibs-devel-4.14.8-11.el7_7.ppc.rpm kdelibs-devel-4.14.8-11.el7_7.ppc64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.ppc.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.ppc64.rpm s390x: kdelibs-4.14.8-11.el7_7.s390.rpm kdelibs-4.14.8-11.el7_7.s390x.rpm kdelibs-common-4.14.8-11.el7_7.s390x.rpm kdelibs-debuginfo-4.14.8-11.el7_7.s390.rpm kdelibs-debuginfo-4.14.8-11.el7_7.s390x.rpm kdelibs-devel-4.14.8-11.el7_7.s390.rpm kdelibs-devel-4.14.8-11.el7_7.s390x.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.s390.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.s390x.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: kde-settings-19-23.10.el7_7.src.rpm kdelibs-4.14.8-11.el7_7.src.rpm noarch: kde-settings-19-23.10.el7_7.noarch.rpm kde-settings-ksplash-19-23.10.el7_7.noarch.rpm kde-settings-plasma-19-23.10.el7_7.noarch.rpm kde-settings-pulseaudio-19-23.10.el7_7.noarch.rpm qt-settings-19-23.10.el7_7.noarch.rpm x86_64: kdelibs-4.14.8-11.el7_7.i686.rpm kdelibs-4.14.8-11.el7_7.x86_64.rpm kdelibs-common-4.14.8-11.el7_7.x86_64.rpm kdelibs-debuginfo-4.14.8-11.el7_7.i686.rpm kdelibs-debuginfo-4.14.8-11.el7_7.x86_64.rpm kdelibs-devel-4.14.8-11.el7_7.i686.rpm kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): noarch: kde-settings-minimal-19-23.10.el7_7.noarch.rpm kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verifythe signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-14744 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXW6mb9zjgjWX9erEAQiw0RAAhNN2C/nEIChc7w6wakv+TRHxmENmhjJH mmEupc5Hei3bSCPYBBLKn9+J3pv9eN6l3YREFml/cdssoMMP74Op3U/8i8mDYH2R ONXhA5Eh1eTUqe4v+kmFSn2GHy4t6SEipgXFkybLhZsCrek7R8ieoR1JM4z83LOv ijMHoZL4ChuS8He5A+g99PGya/kpizFSDzBD2R2the8aYybQ/7n3eNJ7zWHj6aR7 dJCQm13yBUiuEUOTnkn+0MQMIGQEE1PYmk5AKUztXfvip6trsRV2Ypnri8ds6/qj QuBCfJQqlyKlXbXoLhg4IB3yKeuCQ42OnLo2bciJvQi0ayicrHCciV7qoWCDl9Ff ViLoGUA4twNr88yRRIGdGJKMnCB+onm+ZT9w77SaVpRIXX/VjSXbh78x85x4+9wf M8gNhcTAicTTkHfAv3VKGwXbhMaZq7bvDpNpxtsm+Qi8mYgQ0DnwgBSCUH7gwARP XTeauIKoonztvjFLSeOIroPZdw7JjZ25FI57EUE9pkIyL+Jf3O2gNI23rJ+Ogo/J 0HGExkRSPcrfED/lqGVTPuYboWofelxPwX1m8B2zGyXfSShlFlX65siAt7ELkY25 DzkFpd0w7VRF2Rug+ZjwooXKUDglb6nXWbTY+hHCdttc93ildGkCA6tBNbIVGzXM 180wxDMpjJw=gSSD -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Oracle has released a significant security update concerning Oracle Linux and its database tools. Urgent patch accessible immediately.. Red Hat Enterprise Linux,kdelibs,kde-settings,security advisory,code execution. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 03, 2019 Important Red Hat
89

Fedora 29: 2019-9f2ee52c88 Critical: kdelibs3 Code Execution Risk

This update fixes **CVE-2019-14744 (kconfig arbitrary shell code execution)** in the KDE 3 compatibility version of kdelibs used by legacy KDE 3 applications. The full list of fixes in this `kdelibs3` build: * fixes **CVE-2019-14744** - `kconfig`: malicious `.desktop` files (and others) would execute code. KConfig had a well-meaning feature that allowed configuration files to execute arbitrary. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-9f2ee52c88 2019-08-19 02:28:49.021905 --------------------------------------------------------------------------------Name : kdelibs3 Product : Fedora 29 Version : 3.5.10 Release : 101.fc29 URL : https://kde.org/ Summary : KDE 3 Libraries Description : Libraries for KDE 3: KDE Libraries included: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation). --------------------------------------------------------------------------------Update Information: This update fixes **CVE-2019-14744 (kconfig arbitrary shell code execution)** in the KDE 3 compatibility version of kdelibs used by legacy KDE 3 applications. The full list of fixes in this `kdelibs3` build: * fixes **CVE-2019-14744** -`kconfig`: malicious `.desktop` files (and others) would execute code. KConfig had a well-meaning feature that allowed configuration files to execute arbitrary shell commands. Unfortunately, this could be abused by untrusted `.desktop` files to execute arbitrary code as the target user, without the user even running the `.desktop` file. Therefore, this update removes that ill-fated feature. (Backported by Kevin Kofler from upstream: `kf5-kconfig` fix by David Faure, `kdelibs` 4 backport by Kai Uwe Broulik.) * adds native support for **xdg-user-dirs** for *Desktop* and *Documents*, without shelling outto `xdg-user-dir` from the config file. This is needed due to the above security fix. (This feature was previously implemented in the Fedora `kde-settings` by shelling out to `xdg-user-dir` from the config file using the KConfig feature removed above.) (Backported by Kevin Kofler from Trinity Desktop / Timothy Pearson.) * fixes a **KJS double-free** that could crash legacy KDE 3 applications such as Quanta Plus when trying to execute JavaScript. (Backported by OpenSUSE / Wolfgang Bauer from Trinity Desktop / Timothy Pearson.) --------------------------------------------------------------------------------ChangeLog: * Sat Aug 10 2019 Kevin Kofler - 3.5.10-101 - Backport CVE-2019-14744 fix by David Faure and Kai Uwe Broulik from kdelibs 4 - Backport native xdg-user-dirs support by Timothy Pearson from Trinity (needed to fix the regression that would otherwise result from the above security fix) - Backport KJS double-free fix by Timothy Pearson (backport by wbauer/OpenSUSE) * Thu Jul 25 2019 Fedora Release Engineering - 3.5.10-100 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Thu Apr 11 2019 Richard Shaw - 3.5.10-99 - Rebuild for OpenEXR 2.3.0. * Fri Feb 1 2019 Fedora Release Engineering - 3.5.10-98 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Sat Jan 5 2019 Kevin Kofler - 3.5.10-97 - Rebuild for the new hardcoded qt3 build key in Rawhide - Fix aarch64 FTBFS due to libtool not liking the file output on *.so files --------------------------------------------------------------------------------References: [ 1 ] Bug #1740138 - CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction https://bugzilla.redhat.com/show_bug.cgi?id=1740138 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-9f2ee52c88' at the command line.For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Essential patch released for Fedora 30, addressing kdelibs4 vulnerability: potential code execution threat via kconfig settings.. Fedora Update, kdelibs3 Security, Code Execution Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 18, 2019 Critical Fedora
99

Slackware: 2019-220-01 Moderate: Kdelibs Malicious Code Exploit

New kdelibs packages are available for Slackware 14.2 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] kdelibs (SSA:2019-220-01) New kdelibs packages are available for Slackware 14.2 and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/kdelibs-4.14.38-i586-1_slack14.2.txz: Upgraded. kconfig: malicious .desktop files (and others) would execute code. For more information, see: https://mail.kde.org/pipermail/kde-announce/2019-August/000047.html https://www.cve.org/CVERecord?id=CVE-2019-14744 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.2 package: bf9cdc634d392f7c05561a7ddc298388 kdelibs-4.14.38-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 3646da04eed2835db47afb3bab02c78b kdelibs-4.14.38-x86_64-1_slack14.2.txz Slackware -current package: a88a3859f1f7fb57df6579ba45153e80 kde/kdelibs-4.14.38-i586-4.txz Slackware x86_64 -current package: cb52242ec03ff9430894b1d7aee206cf kde/kdelibs-4.14.38-x86_64-4.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg kdelibs-4.14.38-i586-1_slack14.2.txz +-----+ . Updated kdelibs packages for Slackware 14.2 and current address a serious security flaw that affects users.. Kdelibs Update, Slackware Security, Package Upgrade, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 08, 2019 Important Slackware
199

CentOS 7: CESA-2017-1264 Critical Kdelibs Update with Upstream Details

Upstream details at : https://access.redhat.com/errata/RHSA-2017:1264.html. CentOS Errata and Security Advisory 2017:1264 Important Upstream details at : https://access.redhat.com/errata/RHSA-2017:1264.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: f3e22666fba8c8111928a8f24136d3c9264c9ff493a7ed9e835a6bf5d7ce7140 kdelibs-4.14.8-6.el7_3.i686.rpm 94f689579faf8da4d7ad45123bb2c06bc11489165fef94b6147f51d31bcb30e8 kdelibs-4.14.8-6.el7_3.x86_64.rpm f7b0fc9c737d4b1bde539fe0ad6244197f2f33394af0681cfcf57140b5298b2a kdelibs-apidocs-4.14.8-6.el7_3.noarch.rpm 954c2ecab2f8bb2366f3b1877650dde9756c351b9a05143c9bde1d932decb191 kdelibs-common-4.14.8-6.el7_3.x86_64.rpm 873ec7107fc9f785552ed6364cab5177843b68eee619ddb23581980fcca75cc2 kdelibs-devel-4.14.8-6.el7_3.i686.rpm 8ba9a2644e75f5e404f6a41070fa4954e9e309ecc8e1fd6342b56cdc307c877c kdelibs-devel-4.14.8-6.el7_3.x86_64.rpm 0119fe8e7df71838bf35a67f96888e310b7f25f8c86282acf8474b03ae7326d5 kdelibs-ktexteditor-4.14.8-6.el7_3.i686.rpm 64978ded4630c6f325b78170824280d86bf2a1566232b9e8e5025992162ab858 kdelibs-ktexteditor-4.14.8-6.el7_3.x86_64.rpm Source: c2931314523bca3fb71d17d9da6bc61d118021c46ac3f70c7f4290b0b000900c kdelibs-4.14.8-6.el7_3.src.rpm -- Johnny Hughes CentOS Project { http://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . CentOS Errata and Security Advisory 2023:7521 regarding the glibc package update contains crucial details from upstream developers.. CentOS 7,kdelibs update,security patch,important updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 22, 2017 Critical CentOS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200