An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for kleopatra =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F Announcement ID: openSUSE-SU-2020:1754-1 Rating: moderate References: #1177932 Cross-References: CVE-2020-24972 Affected Products: openSUSE Backports SLE-15-SP1 =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F An update that fixes one vulnerability is now available. Description: This update for kleopatra fixes the following issues: - CVE-2020-24972: Add upstream patch to prevent potential arbitrary code execution (boo#1177932): This update was imported from the openSUSE:Leap:15.1:Update update proje= ct. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended instal= lation methods like YaST online=5Fupdate or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-1754=3D1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86=5F64): kleopatra-18.12.3-bp151.3.3.1 - openSUSE Backports SLE-15-SP1 (noarch): kleopatra-lang-18.12.3-bp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2020-24972.html https://bugzilla.suse.com/1177932 -- To unsubscribe, e-mail:
The Kleopatra component before 20.07.80 for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary library. (CVE-2020-24972). . MGASA-2020-0425 - Updated kleopatra packages fix a security vulnerability Publication date: 15 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0425.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-24972 The Kleopatra component before 20.07.80 for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary library. (CVE-2020-24972). References: - https://bugs.mageia.org/show_bug.cgi?id=27455 - https://lists.fedoraproject.org/archives/list/
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for kleopatra ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1754-1 Rating: moderate References: #1177932 Cross-References: CVE-2020-24972 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kleopatra fixes the following issues: - CVE-2020-24972: Add upstream patch to prevent potential arbitrary code execution (boo#1177932): This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-1754=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): kleopatra-18.12.3-bp151.3.3.1 - openSUSE Backports SLE-15-SP1 (noarch): kleopatra-lang-18.12.3-bp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2020-24972.html https://bugzilla.suse.com/1177932 -- . An openSUSE Security Update for gimp resolves a vulnerability related to remote exploitation. Ensure safety with the most recent update.. openSUSE Security Update, kleopatra, Arbitrary Code Execution, Software Patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for kleopatra ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1723-1 Rating: moderate References: #1177932 Cross-References: CVE-2020-24972 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kleopatra fixes the following issues: - CVE-2020-24972: Add upstream patch to prevent potential arbitrary code execution (boo#1177932): Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-1723=1 Package List: - openSUSE Leap 15.1 (noarch): kleopatra-lang-18.12.3-lp151.2.4.1 - openSUSE Leap 15.1 (x86_64): kleopatra-18.12.3-lp151.2.4.1 kleopatra-debuginfo-18.12.3-lp151.2.4.1 kleopatra-debugsource-18.12.3-lp151.2.4.1 References: https://www.suse.com/security/cve/CVE-2020-24972.html https://bugzilla.suse.com/1177932 -- . openSUSE has released a security update for libxml2 addressing a moderate severity vulnerability that could lead to privilege escalation.. Security Update, openSUSE, Kleopatra Patch, Arbitrary Code Execution. . LinuxSecurity.com Team
A vulnerability in Kleopatra allows arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202008-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Kleopatra: Remote code execution Date: August 30, 2020 Bugs: #739556 ID: 202008-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in Kleopatra allows arbitrary execution of code. Background ========= Kleopatra is a certificate manager and a universal crypto GUI. It supports managing X.509 and OpenPGP certificates in the GpgSM keybox and retrieving certificates from LDAP servers. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 kde-apps/kleopatra < 20.04.3-r1 > = 20.04.3-r1 Description ========== Kleopatra did not safely escape command line parameters provided by URLs, which it configures itself to handle. Impact ===== A remote attacker could entice a user to process a specially crafted URL via openpgp4fpr handler, possibly resulting in execution of arbitrary code with the privileges of the process, or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Kleopatra users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =kde-apps/kleopatra-20.04.3-r1" References ========= [ 1 ] CVE-2020-24972 https://nvd.nist.gov/vuln/detail/CVE-2020-24972 Availability =========== This GLSA and any updates to it are available for viewing at the GentooSecurity Website: https://security.gentoo.org/glsa/202008-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.