drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen von Code mit höheren Privilegien in KDE Software Compilation
Name: |
Ausführen von Code mit höheren Privilegien in KDE Software Compilation |
|
ID: |
USN-3286-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 14.04 LTS |
|
Datum: |
Mo, 15. Mai 2017, 16:40 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8422 |
|
Applikationen: |
KDE Software Compilation |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============4341331472168503070== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="40JXhwJaFoSFC0enWXJpRGHc7EtVqtDkC"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --40JXhwJaFoSFC0enWXJpRGHc7EtVqtDkC Content-Type: multipart/mixed; boundary="GukxJRF9DGgjwxVb0Udd9vDv8n6j3Iixi" From: Marc Deslauriers <marc.deslauriers@canonical.com> Reply-To: Ubuntu Security <security@ubuntu.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <2a0e18d0-4981-65e9-e415-ffa2d1d14425@canonical.com> Subject: [USN-3286-1] KDE-Libs vulnerability
--GukxJRF9DGgjwxVb0Udd9vDv8n6j3Iixi Content-Type: text/plain; charset=utf- Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-3286-1 May 15, 2017
kde4libs vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
KDE-Libs could be made to run programs as an administrator if it received specially crafted input.
Software Description: - kde4libs: KDE 4 core applications and libraries
Details:
Sebastian Krahmer discovered that the KDE-Libs Kauth component incorrectly checked services invoking D-Bus. A local attacker could use this issue to gain root privileges.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.04 LTS: kdelibs5-plugins 4:4.13.3-0ubuntu0.5
After a standard system update you need to reboot your computer to make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-3286-1 CVE-2017-8422
Package Information: https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.3-0ubuntu0.5
--GukxJRF9DGgjwxVb0Udd9vDv8n6j3Iixi--
--40JXhwJaFoSFC0enWXJpRGHc7EtVqtDkC Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2
iQIcBAEBCgAGBQJZGa88AAoJEGVp2FWnRL6TKeoP/i8HE4k+1R3YkLRZWmCHvmA8 d+dWD8FGTMLeIYJIM5fe4DzHZv69+EAo461Kh9jI59/MxqKEWyvSMn1lVavROBHh otzZHDnm83hWc/ZfD/PTa7MyqDYUzwl2ahb+2E2X4PIx6Ko9taJK4c36CmK5ZYVk fcVcgRGqMK8ibETwcfaxLH4IVnb/3rGd20uPpMnRT14l3I/+UkVJi+rTWabvg76U OvJaG/hKn97vK7KhA7zjU2Ai4HIDHi2xOLrWolS+ZQuVb0BXzy9grYgRoz4ztnsj ac7MPhF4KODLFkc5MzSAHAt7j1kgZ236ehOLlH2IxKhoO9HUQ29wsnrx6g3XzgGC 8lz2x7PkMH3VPhJ4c9tA6dTvLm4NsDokOA5lh74ZG9uCkR8tDa9i85HOpQlnaLLV KhghJNJNDIyVt8SSg2v5tR2kyUyGSaMJCoPZirpWrbM/C7ip0YBMLR+cUdkcn/ac XKzthIi5m3Esgf3blfbpmbkq2rMEti0SKrrRibsqvyXZUV7XTsqHOrL4ZNNZtu8E TzqaUGnaAPGCgZpxMltZmLZvUokDaK8Sy3pk0rnUjoxAHDOIqsSRiVI9rVnFTncr X70eGKkbwaSzhE0nFoBPv5SpVmHg3DFh4twed+UgwKDhZlJNKBwyC7uZolSsqt+g fGIiASjVuA3qhKkzq3nj =X9Av -----END PGP SIGNATURE-----
--40JXhwJaFoSFC0enWXJpRGHc7EtVqtDkC--
--===============4341331472168503070== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============4341331472168503070==--
|
|
|
|