|
|
Subscribe / Log in / New account

Mageia alert MGASA-2017-0473 (kdebase4-runtime)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2017-0473: Updated kdebase4-runtime packages fix security vulnerability
Date:  Sun, 31 Dec 2017 01:10:56 +0100
Message-ID:  <20171231001056.2FE949FD44@duvel.mageia.org>

MGASA-2017-0473 - Updated kdebase4-runtime packages fix security vulnerability Publication date: 31 Dec 2017 URL: https://advisories.mageia.org/MGASA-2017-0473.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-7787 Description: A user could sneak an unicode string terminator in the kdesu invocation, which could hide the fact that more commands could be executed (CVE-2016-7787). References: - https://bugs.mageia.org/show_bug.cgi?id=19488 - http://openwall.com/lists/oss-security/2016/09/29/7 - https://lists.opensuse.org/opensuse-updates/2016-10/msg00... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7787 SRPMS: - 5/core/kdebase4-runtime-4.14.3-5.1.mga5


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds