Lucene search

K
centosCentOS ProjectCESA-2019:2141
HistoryAug 30, 2019 - 3:07 a.m.

kcm_colors, kde, kdeclassic, kdelibs, kgreeter, khotkeys, kinfocenter, kmag, kmenuedit, ksysguard, ksysguardd, kwin, libkworkspace, oxygen, plasma, qt, virtuoso security update

2019-08-3003:07:33
CentOS Project
lists.centos.org
77

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.005 Low

EPSS

Percentile

77.1%

CentOS Errata and Security Advisory CESA-2019:2141

The K Desktop Environment (KDE) is a graphical desktop environment for the X Window System. The kdelibs packages include core libraries for the K Desktop Environment.

The kde-workspace packages consist of components providing the KDE graphical desktop environment.

Security Fix(es):

  • kde-workspace: Missing sanitization of notifications allows to leak client IP address via IMG element (CVE-2018-6790)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-cr-announce/2019-August/032195.html
https://lists.centos.org/pipermail/centos-cr-announce/2019-August/032196.html
https://lists.centos.org/pipermail/centos-cr-announce/2019-August/032197.html
https://lists.centos.org/pipermail/centos-cr-announce/2019-August/032201.html
https://lists.centos.org/pipermail/centos-cr-announce/2019-August/032448.html

Affected packages:
kcm_colors
kde-settings
kde-settings-ksplash
kde-settings-minimal
kde-settings-plasma
kde-settings-pulseaudio
kde-style-oxygen
kde-workspace
kde-workspace-devel
kde-workspace-ksplash-themes
kde-workspace-libs
kdeclassic-cursor-theme
kdelibs
kdelibs-apidocs
kdelibs-common
kdelibs-devel
kdelibs-ktexteditor
kgreeter-plugins
khotkeys
khotkeys-libs
kinfocenter
kmag
kmenuedit
ksysguard
ksysguard-libs
ksysguardd
kwin
kwin-gles
kwin-gles-libs
kwin-libs
libkworkspace
oxygen-cursor-themes
plasma-scriptengine-python
plasma-scriptengine-ruby
qt-settings
virtuoso-opensource
virtuoso-opensource-utils

Upstream details at:
https://access.redhat.com/errata/RHSA-2019:2141

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.005 Low

EPSS

Percentile

77.1%