Gentoo Archives: gentoo-announce

From: "Christopher Díaz Riveros" <chrisadr@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201803-09 ] KDE Plasma Workspaces: Multiple vulnerabilities
Date: Mon, 19 Mar 2018 01:16:49
Message-Id: 1521422149.2499.8.camel@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201803-09
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: KDE Plasma Workspaces: Multiple vulnerabilities
9 Date: March 19, 2018
10 Bugs: #647106
11 ID: 201803-09
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in KDE Plasma Workspaces, the
19 worst of which allows local attackers to execute arbitrary commands.
20
21 Background
22 ==========
23
24 KDE Plasma workspace is a widget based desktop environment designed to
25 be fast and efficient.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 kde-plasma/plasma-workspace
34 < 5.11.5-r1 >= 5.11.5-r1
35
36 Description
37 ===========
38
39 Multiple vulnerabilities have been discovered in KDE Plasma Workspaces.
40 Please review the referenced CVE identifiers for details.
41
42 Impact
43 ======
44
45 An attacker could execute arbitrary commands via specially crafted
46 thumb drive's volume labels or obtain sensitive information via
47 specially crafted notifications.
48
49 Workaround
50 ==========
51
52 Users should mount removable devices with Dolphin instead of the device
53 notifier.
54
55 Users should disable notifications.
56
57 Resolution
58 ==========
59
60 All KDE Plasma Workspace users should upgrade to the latest version:
61
62 # emerge --sync
63 # emerge --ask --oneshot -v ">=kde-plasma/plasma-workspace-5.11.5-r1"
64
65 References
66 ==========
67
68 [ 1 ] CVE-2018-6790
69 https://nvd.nist.gov/vuln/detail/CVE-2018-6790
70 [ 2 ] CVE-2018-6791
71 https://nvd.nist.gov/vuln/detail/CVE-2018-6791
72
73 Availability
74 ============
75
76 This GLSA and any updates to it are available for viewing at
77 the Gentoo Security Website:
78
79 https://security.gentoo.org/glsa/201803-09
80
81 Concerns?
82 =========
83
84 Security is a primary focus of Gentoo Linux and ensuring the
85 confidentiality and security of our users' machines is of utmost
86 importance to us. Any security concerns should be addressed to
87 security@g.o or alternatively, you may file a bug at
88 https://bugs.gentoo.org.
89
90 License
91 =======
92
93 Copyright 2018 Gentoo Foundation, Inc; referenced text
94 belongs to its owner(s).
95
96 The contents of this document are licensed under the
97 Creative Commons - Attribution / Share Alike license.
98
99 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature