[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3849-1 kde4libs -- kde4libs

ID: oval:org.secpod.oval:def:602878Date: (C)2017-05-17   (M)2023-04-17
Class: PATCHFamily: unix




Several vulnerabilities were discovered in kde4libs, the core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2017-6410 Itzik Kotler, Yonatan Fridburg and Amit Klein of Safebreach Labs reported that URLs are not sanitized before passing them to FindProxyForURL, potentially allowing a remote attacker to obtain sensitive information via a crafted PAC file. CVE-2017-8422 Sebastian Krahmer from SUSE discovered that the KAuth framework contains a logic flaw in which the service invoking dbus is not properly checked. This flaw allows spoofing the identity of the caller and gaining root privileges from an unprivileged account.

Platform:
Debian 8.x
Product:
kdelibs-bin
kdelibs5-dev
Reference:
DSA-3849-1
CVE-2017-6410
CVE-2017-8422
CVE    2
CVE-2017-6410
CVE-2017-8422
CPE    3
cpe:/a:kde:kdelibs5-dev
cpe:/o:debian:debian_linux:8.x
cpe:/a:kde:kdelibs-bin

© SecPod Technologies