Untrusted search path in ktexteditor - CVE-2022-23853

 

Untrusted search path in ktexteditor - CVE-2022-23853

Published: January 31, 2022


Vulnerability identifier: #VU60188
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23853
CWE-ID: CWE-426
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the way application searches for executable files. A local user can place a malicious binary file into a current working directory, trick the victim into running the application and execute arbitrary code with elevated privileges.


Affected software

ktexteditor
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Fedora
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
libqt5-qtbase-debugsource
libQt5Sql5-sqlite
libQt5Sql5-sqlite-debuginfo
libQt5Sql5-unixODBC
libQt5Sql5-unixODBC-debuginfo
libQt5Test-devel
libQt5Test5
libQt5Test5-debuginfo
libQt5Widgets-devel
libQt5Widgets5
libQt5Widgets5-debuginfo
libQt5Xml-devel
libQt5Xml5
libQt5Xml5-debuginfo
libqt5-qtbase-common-devel
libqt5-qtbase-common-devel-debuginfo
libQt5Concurrent5
libqt5-qtbase-devel
libqt5-qtbase-platformtheme-gtk3
libqt5-qtbase-platformtheme-gtk3-debuginfo
libQt5Core-private-headers-devel
libQt5DBus-private-headers-devel
libQt5Gui-private-headers-devel
libQt5KmsSupport-private-headers-devel
libQt5Network-private-headers-devel
libQt5OpenGL-private-headers-devel
libQt5PlatformSupport-private-headers-devel
libQt5PrintSupport-private-headers-devel
libQt5Sql-private-headers-devel
libQt5Test-private-headers-devel
libQt5Widgets-private-headers-devel
libqt5-qtbase-private-headers-devel
libQt5Sql5-postgresql
libQt5Concurrent-devel
libQt5Concurrent5-debuginfo
libQt5Core-devel
libQt5Core5
libQt5Core5-debuginfo
libQt5DBus-devel
libQt5DBus-devel-debuginfo
libQt5DBus5
libQt5DBus5-debuginfo
libQt5Gui-devel
libQt5Gui5
libQt5Gui5-debuginfo
libQt5KmsSupport-devel-static
libQt5Network-devel
libQt5Network5
libQt5OpenGL-devel
libQt5Sql5-postgresql-debuginfo
libQt5Sql5-mysql-debuginfo
libQt5Sql5-mysql
libQt5Sql5-debuginfo
libQt5Sql5
libQt5Sql-devel
libQt5PrintSupport5-debuginfo
libQt5PrintSupport5
libQt5PrintSupport-devel
libQt5PlatformSupport-devel-static
libQt5PlatformHeaders-devel
libQt5OpenGLExtensions-devel-static
libQt5OpenGL5-debuginfo
libQt5OpenGL5
libQt5Network5-debuginfo
kde-frameworks/ktexteditor
kate

How to mitigate CVE-2022-23853

Install updates from vendor's website.

ktexteditor - update to 5.91.0
libqt5-qtbase-debugsource - update to 5.12.7-4.17.1
libQt5Sql5-sqlite - update to 5.12.7-4.17.1
libQt5Sql5-sqlite-debuginfo - update to 5.12.7-4.17.1
libQt5Sql5-unixODBC - update to 5.12.7-4.17.1
libQt5Sql5-unixODBC-debuginfo - update to 5.12.7-4.17.1
libQt5Test-devel - update to 5.12.7-4.17.1
libQt5Test5 - update to 5.12.7-4.17.1
libQt5Test5-debuginfo - update to 5.12.7-4.17.1
libQt5Widgets-devel - update to 5.12.7-4.17.1
libQt5Widgets5 - update to 5.12.7-4.17.1
libQt5Widgets5-debuginfo - update to 5.12.7-4.17.1
libQt5Xml-devel - update to 5.12.7-4.17.1
libQt5Xml5 - update to 5.12.7-4.17.1
libQt5Xml5-debuginfo - update to 5.12.7-4.17.1
libqt5-qtbase-common-devel - update to 5.12.7-4.17.1
libqt5-qtbase-common-devel-debuginfo - update to 5.12.7-4.17.1
libQt5Concurrent5 - update to 5.12.7-4.17.1
libqt5-qtbase-devel - update to 5.12.7-4.17.1
libqt5-qtbase-platformtheme-gtk3 - update to 5.12.7-4.17.1
libqt5-qtbase-platformtheme-gtk3-debuginfo - update to 5.12.7-4.17.1
libQt5Core-private-headers-devel - update to 5.12.7-4.17.1
libQt5DBus-private-headers-devel - update to 5.12.7-4.17.1
libQt5Gui-private-headers-devel - update to 5.12.7-4.17.1
libQt5KmsSupport-private-headers-devel - update to 5.12.7-4.17.1
libQt5Network-private-headers-devel - update to 5.12.7-4.17.1
libQt5OpenGL-private-headers-devel - update to 5.12.7-4.17.1
libQt5PlatformSupport-private-headers-devel - update to 5.12.7-4.17.1
libQt5PrintSupport-private-headers-devel - update to 5.12.7-4.17.1
libQt5Sql-private-headers-devel - update to 5.12.7-4.17.1
libQt5Test-private-headers-devel - update to 5.12.7-4.17.1
libQt5Widgets-private-headers-devel - update to 5.12.7-4.17.1
libqt5-qtbase-private-headers-devel - update to 5.12.7-4.17.1
libQt5Sql5-postgresql - update to 5.12.7-4.17.1
libQt5Concurrent-devel - update to 5.12.7-4.17.1
libQt5Concurrent5-debuginfo - update to 5.12.7-4.17.1
libQt5Core-devel - update to 5.12.7-4.17.1
libQt5Core5 - update to 5.12.7-4.17.1
libQt5Core5-debuginfo - update to 5.12.7-4.17.1
libQt5DBus-devel - update to 5.12.7-4.17.1
libQt5DBus-devel-debuginfo - update to 5.12.7-4.17.1
libQt5DBus5 - update to 5.12.7-4.17.1
libQt5DBus5-debuginfo - update to 5.12.7-4.17.1
libQt5Gui-devel - update to 5.12.7-4.17.1
libQt5Gui5 - update to 5.12.7-4.17.1
libQt5Gui5-debuginfo - update to 5.12.7-4.17.1
libQt5KmsSupport-devel-static - update to 5.12.7-4.17.1
libQt5Network-devel - update to 5.12.7-4.17.1
libQt5Network5 - update to 5.12.7-4.17.1
libQt5OpenGL-devel - update to 5.12.7-4.17.1
libQt5Sql5-postgresql-debuginfo - update to 5.12.7-4.17.1
libQt5Sql5-mysql-debuginfo - update to 5.12.7-4.17.1
libQt5Sql5-mysql - update to 5.12.7-4.17.1
libQt5Sql5-debuginfo - update to 5.12.7-4.17.1
libQt5Sql5 - update to 5.12.7-4.17.1
libQt5Sql-devel - update to 5.12.7-4.17.1
libQt5PrintSupport5-debuginfo - update to 5.12.7-4.17.1
libQt5PrintSupport5 - update to 5.12.7-4.17.1
libQt5PrintSupport-devel - update to 5.12.7-4.17.1
libQt5PlatformSupport-devel-static - update to 5.12.7-4.17.1
libQt5PlatformHeaders-devel - update to 5.12.7-4.17.1
libQt5OpenGLExtensions-devel-static - update to 5.12.7-4.17.1
libQt5OpenGL5-debuginfo - update to 5.12.7-4.17.1
libQt5OpenGL5 - update to 5.12.7-4.17.1
libQt5Network5-debuginfo - update to 5.12.7-4.17.1
kde-frameworks/ktexteditor - update to 5.90.0-r2
kate - addressed in versions 21.12.2-1.el8, 21.12.2-1.fc35

External References

Related Security Bulletins