Get a Pentest and security assessment of your IT network.

2021-current

CVE-2019-7443 – KDE KAuth before 5.55 allows the passing of parameters with arbitrary typ

KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7443

Reference (s):

  • https://bugzilla.suse.com/show_bug.cgi?id=1124863
  • http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00060.html
  • http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00065.html
  • https://cgit.kde.org/kauth.git/commit/?id=fc70fb0161c1b9144d26389434d34dd135cd3f4a
  • https://lists.fedoraproject.org/archives/list/[email protected]/message/DAWLQKTUQJOAPXOFWJQAQCA4LVM2P45F/
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-9235 - Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos

2021-current

CVE-2020-0829 - A remote code execution vulnerability exists in the way that the ChakraCo

2021-current

CVE-2020-14828 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Ser