Input validation error in kauth - CVE-2019-7443
Published: February 27, 2019
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input passed parameters with arbitrary types to helpers running as root over DBus. A local user can perform denial of service attack or elevate privileges on the system.
Affected software
Fedora
SUSE Linux
Opensuse
Ubuntu
libkf5auth-data (Ubuntu package)
libkf5auth5 (Ubuntu package)
kf5-kauth
How to mitigate CVE-2019-7443
libkf5auth-data (Ubuntu package) - update to Ubuntu Pro
libkf5auth5 (Ubuntu package) - update to Ubuntu Pro
kf5-kauth - addressed in versions 5.52.0-2.el7, 5.54.0-2.fc28, 5.54.0-2.fc29
External References
Related Security Bulletins
- Privilege escalation in KDE kauth
- OpenSUSE Linux update for kauth
- OpenSUSE Linux update for kauth
- OpenSUSE Linux update for kauth
- OpenSUSE Linux update for kauth
- OpenSUSE Linux update for kauth
- Ubuntu update for kauth
- Fedora 29 update for kf5-kauth
- Fedora 28 update for kf5-kauth
- Fedora EPEL 7 update for kf5-kauth