New plasma-workspace packages are available for Slackware 15.0 to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] plasma-workspace (SSA:2024-240-02) New plasma-workspace packages are available for Slackware 15.0 to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/plasma-workspace-5.23.5-i586-4_slack15.0.txz: Rebuilt. This update patches a security issue: ksmserver: Unauthorized users can access session manager. Thanks to pbslxw for the heads-up. For more information, see: https://kde.org/info/security/advisory-20240531-1.txt https://www.cve.org/CVERecord?id=CVE-2024-36041 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/plasma-workspace-5.23.5-i586-4_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/plasma-workspace-5.23.5-x86_64-4_slack15.0.txz MD5 signatures: +-------------+ Slackware 15.0 package: 75db0fae92f3534d307a0c3493485b42 plasma-workspace-5.23.5-i586-4_slack15.0.txz Slackware x86_64 15.0 package: 33c25145a5e9c3f68784688f1a823cda plasma-workspace-5.23.5-x86_64-4_slack15.0.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg plasma-workspace-5.23.5-i586-4_slack15.0.txz +-----+ . Updated plasma-workspace versions for Slackware 15.0 address a critical vulnerability in the session manager. Enhance your defense with this upgrade.. Slacware Security Patch, Plasma Workspace Update, Session Access Fix. . LinuxSecurity.comTeam
plasma-workspace would allow unintended access to the session manager.. ========================================================================== Ubuntu Security Notice USN-6843-1 June 26, 2024 plasma-workspace vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: plasma-workspace would allow unintended access to the session manager. Software Description: - plasma-workspace: Plasma Workspace for KF5 Details: Fabian Vogt discovered that Plasma Workspace incorrectly handled connections via ICE. A local attacker could possibly use this issue to gain access to another user's session manager and execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS plasma-workspace 4:5.27.11-0ubuntu4.1 Ubuntu 23.10 plasma-workspace 4:5.27.8-0ubuntu1.1 Ubuntu 22.04 LTS plasma-workspace 4:5.24.7-0ubuntu0.2 Ubuntu 20.04 LTS plasma-workspace 4:5.18.8-0ubuntu0.2 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6843-1 CVE-2024-36041 Package Information: https://launchpad.net/ubuntu/+source/plasma-workspace/4:5.27.11-0ubuntu4.1 https://launchpad.net/ubuntu/+source/plasma-workspace/4:5.27.8-0ubuntu1.1 https://launchpad.net/ubuntu/+source/plasma-workspace/4:5.24.7-0ubuntu0.2 https://launchpad.net/ubuntu/+source/plasma-workspace/4:5.18.8-0ubuntu0.2 . A vulnerability exists in the Plasma Workspace on Ubuntu, allowing unauthorized access. Users must update to secure their systems and prevent risks.. Plasma Workspace, Ubuntu Security, Session Manager Access, Local Attack, Software Update. . Severity:Important. LinuxSecurity.com Team
Unauthorized local user access to the session manager has been fixed in the Plasma Workspace component of the KDE Plasma desktop environment. For Debian 10 buster, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3827-1
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-311 2006-04-17 ---------------------------------------------------------------------Product : Fedora Core 5 Name : gnome-session Version : 2.14.1 Release : 1.fc5.1 Summary : GNOME session manager Description : gnome-session manages a GNOME desktop session. It starts up the other core GNOME components and handles logout and saving the session. ---------------------------------------------------------------------Update Information: Version 2.14.1 ============= Session Manager * Share one GConfClient (Rodrigo Moya) * Plug leaks (Kjartan Maraas) Translators * Ales Nyakhaychyk (be) * Pema Geyleg (dz) * Kostas Papadimas (el) * Laurent Richard (fr) * Gil Osher (he) ---------------------------------------------------------------------* Mon Apr 10 2006 Matthias Clasen - 2.14.1-1.fc5.1 - Update to 2.14.1 ---------------------------------------------------------------------This update can be downloaded from: ffe20f27ec1e3e5277e5758f24870358f0f82e35 SRPMS/gnome-session-2.14.1-1.fc5.1.src.rpm a4dc03add54e6954c5559b4ca8b5584ba238790d ppc/gnome-session-2.14.1-1.fc5.1.ppc.rpm 460266573ea2ef9d64d193ce2fe46c339b77446b ppc/debug/gnome-session-debuginfo-2.14.1-1.fc5.1.ppc.rpm 53fec676a27439514c3f32fe2fbedf1359eb8f1f x86_64/gnome-session-2.14.1-1.fc5.1.x86_64.rpm 59d2b20a40922b8435b54c946eecf7b0ee04e486 x86_64/debug/gnome-session-debuginfo-2.14.1-1.fc5.1.x86_64.rpm f09a658e09baa70e3f0c68bf197712e040eeb4a4 i386/gnome-session-2.14.1-1.fc5.1.i386.rpm a6c45c52ad222417e522fc0da5125c3c9619f11b i386/debug/gnome-session-debuginfo-2.14.1-1.fc5.1.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at. ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.