USN-4100-1: KConfig and KDE libraries vulnerabilities
16 August 2019
KConfig and KDE libraries could be made to crash or run programs if it opened a specially crafted file.
Releases
Packages
Details
It was discovered that KConfig and KDE libraries have a vulnerability
where an attacker could hide malicious code under desktop and
configuration files. (CVE-2019-14744)
It was discovered that KConfig allows remote attackers to write to
arbitrary files via a ../ in a filename in an archive file. (CVE-2016-6232)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 19.04
Ubuntu 18.04
Ubuntu 16.04
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-3042-1: libkemoticons4, kdelibs5-data, kdelibs-bin, libkimproxy4, libkdesu5, kdoctools, libkcmutils4, libkjsembed4, libthreadweaver4, libkfile4, libkprintutils4, libktexteditor4, libnepomukquery4a, libkdeclarative5, libplasma3, libkhtml5, libkio5, libkparts4, libnepomuk4, libkutils4, libkrosscore4, libnepomukutils4, libsolid4, libknotifyconfig4, kdelibs5-plugins, libkdeui5, libkpty4, libkntlm4, libkunitconversion4, libkjsapi4, libkdewebkit5, libknewstuff2-4, libkmediaplayer4, kde4libs, libkde3support4, kdelibs5-dev, libkdnssd4, libkrossui4, libkidletime4, libkdecore5, libknewstuff3-4