CVE-2019-7443

KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kde:kauth:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:opensuse:backports:-:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise:15.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-05-07 19:29

Updated : 2024-02-04 20:20


NVD link : CVE-2019-7443

Mitre link : CVE-2019-7443

CVE.ORG link : CVE-2019-7443


JSON object : View

Products Affected

kde

  • kauth

opensuse

  • leap
  • backports

suse

  • linux_enterprise

fedoraproject

  • fedora
CWE
CWE-20

Improper Input Validation