An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for kconfig, kdelibs4 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1898-1 Rating: important References: #1144600 Cross-References: CVE-2019-14744 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kconfig, kdelibs4 fixes the following issues: - CVE-2019-14744: Fixed a command execution by an shell expansion (boo#1144600). This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2019-1898=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): kconf_update5-5.55.0-bp151.3.8.1 kconfig-devel-5.55.0-bp151.3.8.1 kdelibs4-4.14.38-bp151.9.8.2 kdelibs4-branding-upstream-4.14.38-bp151.9.8.2 kdelibs4-core-4.14.38-bp151.9.8.2 kdelibs4-core-debuginfo-4.14.38-bp151.9.8.2 kdelibs4-debuginfo-4.14.38-bp151.9.8.2 kdelibs4-debugsource-4.14.38-bp151.9.8.2 kdelibs4-doc-4.14.38-bp151.9.8.2 kdelibs4-doc-debuginfo-4.14.38-bp151.9.8.2 libKF5ConfigCore5-5.55.0-bp151.3.8.1 libKF5ConfigGui5-5.55.0-bp151.3.8.1 libkde4-4.14.38-bp151.9.8.2 libkde4-debuginfo-4.14.38-bp151.9.8.2 libkde4-devel-4.14.38-bp151.9.8.2 libkde4-devel-debuginfo-4.14.38-bp151.9.8.2 libkdecore4-4.14.38-bp151.9.8.2 libkdecore4-debuginfo-4.14.38-bp151.9.8.2 libkdecore4-devel-4.14.38-bp151.9.8.2 libkdecore4-devel-debuginfo-4.14.38-bp151.9.8.2 libksuseinstall-devel-4.14.38-bp151.9.8.2 libksuseinstall1-4.14.38-bp151.9.8.2 libksuseinstall1-debuginfo-4.14.38-bp151.9.8.2 - openSUSE Backports SLE-15-SP1 (aarch64_ilp32): kconfig-devel-64bit-5.55.0-bp151.3.8.1 libKF5ConfigCore5-64bit-5.55.0-bp151.3.8.1 libKF5ConfigGui5-64bit-5.55.0-bp151.3.8.1 libkde4-64bit-4.14.38-bp151.9.8.2 libkde4-64bit-debuginfo-4.14.38-bp151.9.8.2 libkdecore4-64bit-4.14.38-bp151.9.8.2 libkdecore4-64bit-debuginfo-4.14.38-bp151.9.8.2 libksuseinstall1-64bit-4.14.38-bp151.9.8.2 libksuseinstall1-64bit-debuginfo-4.14.38-bp151.9.8.2 - openSUSE Backports SLE-15-SP1 (noarch): kdelibs4-apidocs-4.14.38-bp151.9.8.1 libKF5ConfigCore5-lang-5.55.0-bp151.3.8.1 References: https://www.suse.com/security/cve/CVE-2019-14744.html https://bugzilla.suse.com/1144600 -- . A patch has been issued for kconfig and kdelibs4 that mitigates a potential command execution vulnerability within openSUSE.. openSUSE Security Update, kconfig patch, kdelibs4 security, command execution, important security fix. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for kconfig, kdelibs4 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1855-1 Rating: important References: #1144600 Cross-References: CVE-2019-14744 Affected Products: openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kconfig, kdelibs4 fixes the following issues: - CVE-2019-14744: Fixed a command execution by an shell expansion (boo#1144600). This update was imported from the openSUSE:Leap:15.0:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-1855=1 Package List: - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): kconf_update5-5.45.0-bp150.3.8.2 kconf_update5-debuginfo-5.45.0-bp150.3.8.2 kconfig-debugsource-5.45.0-bp150.3.8.2 kconfig-devel-5.45.0-bp150.3.8.2 kconfig-devel-debuginfo-5.45.0-bp150.3.8.2 kdelibs4-4.14.38-bp150.3.8.1 kdelibs4-branding-upstream-4.14.38-bp150.3.8.1 kdelibs4-core-4.14.38-bp150.3.8.1 kdelibs4-doc-4.14.38-bp150.3.8.1 libKF5ConfigCore5-5.45.0-bp150.3.8.2 libKF5ConfigCore5-debuginfo-5.45.0-bp150.3.8.2 libKF5ConfigGui5-5.45.0-bp150.3.8.2 libKF5ConfigGui5-debuginfo-5.45.0-bp150.3.8.2 libkde4-4.14.38-bp150.3.8.1 libkde4-devel-4.14.38-bp150.3.8.1 libkdecore4-4.14.38-bp150.3.8.1 libkdecore4-devel-4.14.38-bp150.3.8.1 libksuseinstall-devel-4.14.38-bp150.3.8.1 libksuseinstall1-4.14.38-bp150.3.8.1 - openSUSE Backports SLE-15(aarch64_ilp32): kconfig-devel-64bit-5.45.0-bp150.3.8.2 kconfig-devel-64bit-debuginfo-5.45.0-bp150.3.8.2 libKF5ConfigCore5-64bit-5.45.0-bp150.3.8.2 libKF5ConfigCore5-64bit-debuginfo-5.45.0-bp150.3.8.2 libKF5ConfigGui5-64bit-5.45.0-bp150.3.8.2 libKF5ConfigGui5-64bit-debuginfo-5.45.0-bp150.3.8.2 libkde4-64bit-4.14.38-bp150.3.8.1 libkdecore4-64bit-4.14.38-bp150.3.8.1 libksuseinstall1-64bit-4.14.38-bp150.3.8.1 - openSUSE Backports SLE-15 (noarch): kdelibs4-apidocs-4.14.38-bp150.3.8.1 libKF5ConfigCore5-lang-5.45.0-bp150.3.8.2 References: https://www.suse.com/security/cve/CVE-2019-14744.html https://bugzilla.suse.com/1144600 -- . This Fedora security patch resolves a critical problem with libinput and systemd, eliminating potential vulnerabilities in command handling.. openSUSE Security Update,kconfig,kdelibs4,command execution,patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for kconfig, kdelibs4 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1851-1 Rating: important References: #1144600 Cross-References: CVE-2019-14744 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kconfig, kdelibs4 fixes the following issues: - CVE-2019-14744: Fixed a command execution by an shell expansion (boo#1144600). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2019-1851=1 Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64): kconf_update5-5.20.0-8.1 kconf_update5-5.26.0-8.1 kconf_update5-5.32.0-7.1 kconf_update5-debuginfo-5.20.0-8.1 kconf_update5-debuginfo-5.26.0-8.1 kconf_update5-debuginfo-5.32.0-7.1 kconfig-debugsource-5.20.0-8.1 kconfig-debugsource-5.26.0-8.1 kconfig-debugsource-5.32.0-7.1 kconfig-devel-5.20.0-8.1 kconfig-devel-5.26.0-8.1 kconfig-devel-5.32.0-7.1 kconfig-devel-debuginfo-5.20.0-8.1 kconfig-devel-debuginfo-5.26.0-8.1 kconfig-devel-debuginfo-5.32.0-7.1 kdelibs4-4.14.18-14.1 kdelibs4-4.14.25-13.1 kdelibs4-4.14.33-7.2 kdelibs4-branding-upstream-4.14.18-14.1 kdelibs4-branding-upstream-4.14.25-13.1 kdelibs4-branding-upstream-4.14.33-7.2 kdelibs4-core-4.14.18-14.1 kdelibs4-core-4.14.25-13.1 kdelibs4-core-4.14.33-7.2 kdelibs4-core-debuginfo-4.14.18-14.1 kdelibs4-core-debuginfo-4.14.25-13.1 kdelibs4-core-debuginfo-4.14.33-7.2 kdelibs4-debuginfo-4.14.18-14.1 kdelibs4-debuginfo-4.14.25-13.1 kdelibs4-debuginfo-4.14.33-7.2 kdelibs4-debugsource-4.14.18-14.1 kdelibs4-debugsource-4.14.25-13.1 kdelibs4-debugsource-4.14.33-7.2 kdelibs4-doc-4.14.18-14.1 kdelibs4-doc-4.14.25-13.1 kdelibs4-doc-4.14.33-7.2 kdelibs4-doc-debuginfo-4.14.18-14.1 kdelibs4-doc-debuginfo-4.14.25-13.1 kdelibs4-doc-debuginfo-4.14.33-7.2 libKF5ConfigCore5-5.20.0-8.1 libKF5ConfigCore5-5.26.0-8.1 libKF5ConfigCore5-5.32.0-7.1 libKF5ConfigCore5-debuginfo-5.20.0-8.1 libKF5ConfigCore5-debuginfo-5.26.0-8.1 libKF5ConfigCore5-debuginfo-5.32.0-7.1 libKF5ConfigGui5-5.20.0-8.1 libKF5ConfigGui5-5.26.0-8.1 libKF5ConfigGui5-5.32.0-7.1 libKF5ConfigGui5-debuginfo-5.20.0-8.1 libKF5ConfigGui5-debuginfo-5.26.0-8.1 libKF5ConfigGui5-debuginfo-5.32.0-7.1 libkde4-4.14.18-14.1 libkde4-4.14.25-13.1 libkde4-4.14.33-7.2 libkde4-debuginfo-4.14.18-14.1 libkde4-debuginfo-4.14.25-13.1 libkde4-debuginfo-4.14.33-7.2 libkde4-devel-4.14.18-14.1 libkde4-devel-4.14.25-13.1 libkde4-devel-4.14.33-7.2 libkdecore4-4.14.18-14.1 libkdecore4-4.14.25-13.1 libkdecore4-4.14.33-7.2 libkdecore4-debuginfo-4.14.18-14.1 libkdecore4-debuginfo-4.14.25-13.1 libkdecore4-debuginfo-4.14.33-7.2 libkdecore4-devel-4.14.18-14.1 libkdecore4-devel-4.14.25-13.1 libkdecore4-devel-4.14.33-7.2 libkdecore4-devel-debuginfo-4.14.18-14.1 libkdecore4-devel-debuginfo-4.14.25-13.1 libkdecore4-devel-debuginfo-4.14.33-7.2 libksuseinstall-devel-4.14.18-14.1 libksuseinstall-devel-4.14.25-13.1 libksuseinstall-devel-4.14.33-7.2 libksuseinstall1-4.14.18-14.1 libksuseinstall1-4.14.25-13.1 libksuseinstall1-4.14.33-7.2 libksuseinstall1-debuginfo-4.14.18-14.1 libksuseinstall1-debuginfo-4.14.25-13.1 libksuseinstall1-debuginfo-4.14.33-7.2 - SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64_ilp32): kconfig-devel-64bit-5.32.0-7.1 kconfig-devel-debuginfo-64bit-5.32.0-7.1 libKF5ConfigCore5-64bit-5.32.0-7.1 libKF5ConfigCore5-debuginfo-64bit-5.32.0-7.1 libKF5ConfigGui5-64bit-5.32.0-7.1 libKF5ConfigGui5-debuginfo-64bit-5.32.0-7.1 libkde4-64bit-4.14.33-7.2 libkde4-debuginfo-64bit-4.14.33-7.2 libkdecore4-64bit-4.14.33-7.2 libkdecore4-debuginfo-64bit-4.14.33-7.2 libksuseinstall1-64bit-4.14.33-7.2 libksuseinstall1-debuginfo-64bit-4.14.33-7.2 - SUSE Package Hub for SUSE Linux Enterprise 12 (noarch): kdelibs4-apidocs-4.14.18-14.1 kdelibs4-apidocs-4.14.25-13.1 kdelibs4-apidocs-4.14.33-7.2 libKF5ConfigCore5-lang-5.20.0-8.1 libKF5ConfigCore5-lang-5.26.0-8.1 libKF5ConfigCore5-lang-5.32.0-7.1 References: https://www.suse.com/security/cve/CVE-2019-14744.html https://bugzilla.suse.com/1144600 -- . The recent update for kconfig and kdelibs4 resolves a significant command execution vulnerability in openSUSE.. openSUSE Security Update,kconfig,kdelibs4,command execution,software patching. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for kdelibs4 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1335-1 Rating: important References: #1036244 Cross-References: CVE-2017-8422 Affected Products: SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Server 12-SP1 SUSE Linux Enterprise Desktop 12-SP2 SUSE Linux Enterprise Desktop 12-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kdelibs4 fixes the following issues: - CVE-2017-8422: This update fixes problem in the DBUS authentication of the kauth framework that could be used to escalate privileges depending on bugs or misimplemented dbus services. (boo#1036244) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-805=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-805=1 - SUSE Linux Enterprise Server 12-SP1: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-805=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-805=1 - SUSE Linux Enterprise Desktop 12-SP1: zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2017-805=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): kdelibs4-debuginfo-4.12.0-10.1 kdelibs4-debugsource-4.12.0-10.1 libkde4-4.12.0-10.1 libkde4-debuginfo-4.12.0-10.1 libkdecore4-4.12.0-10.1 libkdecore4-debuginfo-4.12.0-10.1 libksuseinstall1-4.12.0-10.1 libksuseinstall1-debuginfo-4.12.0-10.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): kdelibs4-debuginfo-4.12.0-10.1 kdelibs4-debugsource-4.12.0-10.1 libkde4-4.12.0-10.1 libkde4-debuginfo-4.12.0-10.1 libkdecore4-4.12.0-10.1 libkdecore4-debuginfo-4.12.0-10.1 libksuseinstall1-4.12.0-10.1 libksuseinstall1-debuginfo-4.12.0-10.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libkde4-32bit-4.12.0-10.1 libkde4-debuginfo-32bit-4.12.0-10.1 libkdecore4-32bit-4.12.0-10.1 libkdecore4-debuginfo-32bit-4.12.0-10.1 libksuseinstall1-32bit-4.12.0-10.1 libksuseinstall1-debuginfo-32bit-4.12.0-10.1 - SUSE Linux Enterprise Server 12-SP1 (ppc64le s390x x86_64): kdelibs4-debuginfo-4.12.0-10.1 kdelibs4-debugsource-4.12.0-10.1 libkde4-4.12.0-10.1 libkde4-debuginfo-4.12.0-10.1 libkdecore4-4.12.0-10.1 libkdecore4-debuginfo-4.12.0-10.1 libksuseinstall1-4.12.0-10.1 libksuseinstall1-debuginfo-4.12.0-10.1 - SUSE Linux Enterprise Server 12-SP1 (s390x x86_64): libkde4-32bit-4.12.0-10.1 libkde4-debuginfo-32bit-4.12.0-10.1 libkdecore4-32bit-4.12.0-10.1 libkdecore4-debuginfo-32bit-4.12.0-10.1 libksuseinstall1-32bit-4.12.0-10.1 libksuseinstall1-debuginfo-32bit-4.12.0-10.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): kdelibs4-debuginfo-4.12.0-10.1 kdelibs4-debugsource-4.12.0-10.1 libkde4-32bit-4.12.0-10.1 libkde4-4.12.0-10.1 libkde4-debuginfo-32bit-4.12.0-10.1 libkde4-debuginfo-4.12.0-10.1 libkdecore4-32bit-4.12.0-10.1 libkdecore4-4.12.0-10.1 libkdecore4-debuginfo-32bit-4.12.0-10.1 libkdecore4-debuginfo-4.12.0-10.1 libksuseinstall1-32bit-4.12.0-10.1 libksuseinstall1-4.12.0-10.1 libksuseinstall1-debuginfo-32bit-4.12.0-10.1 libksuseinstall1-debuginfo-4.12.0-10.1 - SUSE Linux Enterprise Desktop 12-SP1 (x86_64): kdelibs4-debuginfo-4.12.0-10.1 kdelibs4-debugsource-4.12.0-10.1 libkde4-32bit-4.12.0-10.1 libkde4-4.12.0-10.1 libkde4-debuginfo-32bit-4.12.0-10.1 libkde4-debuginfo-4.12.0-10.1 libkdecore4-32bit-4.12.0-10.1 libkdecore4-4.12.0-10.1 libkdecore4-debuginfo-32bit-4.12.0-10.1 libkdecore4-debuginfo-4.12.0-10.1 libksuseinstall1-32bit-4.12.0-10.1 libksuseinstall1-4.12.0-10.1 libksuseinstall1-debuginfo-32bit-4.12.0-10.1 libksuseinstall1-debuginfo-4.12.0-10.1 References: https://www.suse.com/security/cve/CVE-2017-8422.html https://bugzilla.suse.com/1036244 . A security advisory has been issued for kdelibs4 addressing significant vulnerabilities in SUSE, urging users to update promptly.. SUSE Update,kdelibs4 Security,Privilege Escalation Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.