OESA-2024-1601

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1601
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2024-1601.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2024-1601
Upstream
  • CVE-2023-2091
Published
2024-05-17T11:08:02Z
Modified
2025-09-03T06:18:55.047636Z
Summary
youker-assistant security update
Details

Integrated tool to aid in routine system maintenance tasks Kylin Assistant is a tool designed to help Ubuntu and Ubuntu Kylin desktop users manage and maintain many aspects of their working environment conveniently in a single application, providing a consistent user experience.

Security Fix(es):

A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function adjustcpufreqscaling_governer. The manipulation leads to os command injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.4.13 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-226099.(CVE-2023-2091)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:22.03-LTS-SP1 / youker-assistant

Package

Name
youker-assistant
Purl
pkg:rpm/openEuler/youker-assistant&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.3-8.oe2203sp1

Ecosystem specific

{
    "src": [
        "youker-assistant-3.0.3-8.oe2203sp1.src.rpm"
    ],
    "x86_64": [
        "youker-assistant-debugsource-3.0.3-8.oe2203sp1.x86_64.rpm",
        "youker-assistant-3.0.3-8.oe2203sp1.x86_64.rpm",
        "youker-assistant-debuginfo-3.0.3-8.oe2203sp1.x86_64.rpm"
    ],
    "aarch64": [
        "youker-assistant-debugsource-3.0.3-8.oe2203sp1.aarch64.rpm",
        "youker-assistant-3.0.3-8.oe2203sp1.aarch64.rpm",
        "youker-assistant-debuginfo-3.0.3-8.oe2203sp1.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2024-1601.json"