MGASA-2017-0274

Source
https://advisories.mageia.org/MGASA-2017-0274.html
Import Source
https://advisories.mageia.org/MGASA-2017-0274.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0274
Related
Published
2017-08-16T22:32:05Z
Modified
2017-08-16T22:01:58Z
Summary
Updated kauth and kdelibs4 packages fix security vulnerability
Details

Sebastian Krahmer from SUSE discovered that the KAuth framework contains a logic flaw in which the service invoking dbus is not properly checked. This flaw allows spoofing the identity of the caller and gaining root privileges from an unprivileged account (CVE-2017-8422).

References
Credits

Affected packages

Mageia:5 / kauth

Package

Name
kauth
Purl
pkg:rpm/mageia/kauth?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.5.0-1.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / kdelibs4

Package

Name
kdelibs4
Purl
pkg:rpm/mageia/kdelibs4?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.14.30-1.1.mga5

Ecosystem specific

{
    "section": "core"
}