A vulnerability has been found in KTextEditor where local code can be executed without user interaction.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202401-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: KTextEditor: Arbitrary Local Code Execution Date: January 15, 2024 Bugs: #832447 ID: 202401-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been found in KTextEditor where local code can be executed without user interaction. Background ========== Framework providing a full text editor component for KDE. Affected packages ================= Package Vulnerable Unaffected -------------------------- ------------ ------------ kde-frameworks/ktexteditor < 5.90.0-r2 > = 5.90.0-r2 Description =========== A vulnerability has been discovered in KTextEditor. Please review the CVE identifiers referenced below for details. Impact ====== KTextEditor executes binaries without user interaction in a few cases, e.g. KTextEditor will try to check on external file modification via invoking the "git" binary if the file is known in the repository with the new content. Workaround ========== There is no known workaround at this time. Resolution ========== All KTextEditor users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =kde-frameworks/ktexteditor-5.90.0-r2" References ========== [ 1 ] CVE-2022-23853 https://nvd.nist.gov/vuln/detail/CVE-2022-23853 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202401-21 Concerns? ========= Security is a primary focus of GentooLinux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.