MGASA-2019-0083 - Updated kauth packages fix security vulnerability

Publication date: 14 Feb 2019
URL: https://advisories.mageia.org/MGASA-2019-0083.html
Type: security
Affected Mageia releases: 6

KAuth allows to pass parameters with arbitrary types to helpers running as
root over DBus. Certain types can cause crashes and trigger decoding
arbitrary images with dynamically loaded plugins.

References:
- https://bugs.mageia.org/show_bug.cgi?id=24334
- https://kde.org/info/security/advisory-20190209-1.txt

SRPMS:
- 6/core/kauth-5.42.0-1.1.mga6

Mageia 2019-0083: kauth security update

KAuth allows to pass parameters with arbitrary types to helpers running as root over DBus

Summary

KAuth allows to pass parameters with arbitrary types to helpers running as root over DBus. Certain types can cause crashes and trigger decoding arbitrary images with dynamically loaded plugins. References:

References

- https://bugs.mageia.org/show_bug.cgi?id=24334

- https://kde.org/info/security/advisory-20190209-1.txt

Resolution

MGASA-2019-0083 - Updated kauth packages fix security vulnerability

SRPMS

- 6/core/kauth-5.42.0-1.1.mga6

Severity
Publication date: 14 Feb 2019
URL: https://advisories.mageia.org/MGASA-2019-0083.html
Type: security

Related News