It was discovered that any unprivileged user could monitor and send method calls to the ibus bus of another user, due to a misconfiguration during the setup of the DBus server. When ibus is in use, a local attacker, who discovers the UNIX socket used by another user connected on a graphical environment, could use this flaw to intercept all keystrokes of the victim user or modify . MGASA-2019-0284 - Updated ibus packages fix security vulnerability Publication date: 21 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0284.html Type: security Affected Mageia releases: 6, 7 CVE: CVE-2019-14822 It was discovered that any unprivileged user could monitor and send method calls to the ibus bus of another user, due to a misconfiguration during the setup of the DBus server. When ibus is in use, a local attacker, who discoversthe UNIX socket used by another user connected on a graphical environment, could use this flaw to intercept all keystrokes of the victim user or modify input related configurations through DBus method calls (CVE-2019-14822). References: - https://bugs.mageia.org/show_bug.cgi?id=25434 - https://www.openwall.com/lists/oss-security/2019/09/13/1 - https://www.cve.org/CVERecord?id=CVE-2019-14822 SRPMS: - 7/core/ibus-1.5.20-1.1.mga7 - 6/core/ibus-1.5.16-3.1.mga6 . Mageia Security Update MGASA-2019-0285 addresses the critical vulnerability in the libxml library that could potentially allow arbitrary code execution by a malicious user.. Mageia Ibus Update, Security Advisory, DBus Misconfiguration, Unprivileged Users. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.