Your submission was sent successfully! Close

USN-4100-1: KConfig and KDE libraries vulnerabilities

16 August 2019

KConfig and KDE libraries could be made to crash or run programs if it opened a specially crafted file.

Releases

Packages

  • kconfig - configuration settings framework for Qt
  • kde4libs - KDE 4 core applications and libraries

Details

It was discovered that KConfig and KDE libraries have a vulnerability
where an attacker could hide malicious code under desktop and
configuration files. (CVE-2019-14744)

It was discovered that KConfig allows remote attackers to write to
arbitrary files via a ../ in a filename in an archive file. (CVE-2016-6232)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.04
Ubuntu 18.04
Ubuntu 16.04

In general, a standard system update will make all the necessary changes.

Related notices

  • USN-3042-1: libkdewebkit5, libnepomukutils4, libkpty4, libkcmutils4, libkdesu5, libkrosscore4, libknewstuff3-4, kdelibs5-plugins, libkemoticons4, libkutils4, libkdeclarative5, kde4libs, kdelibs-bin, libkfile4, libkdeui5, libkio5, kdoctools, libkde3support4, libkdnssd4, libkjsembed4, libnepomukquery4a, libkjsapi4, libnepomuk4, libsolid4, kdelibs5-dev, libkdecore5, libkunitconversion4, kdelibs5-data, libkimproxy4, libplasma3, libkidletime4, libknewstuff2-4, libkprintutils4, libkparts4, libkntlm4, libkmediaplayer4, libknotifyconfig4, libkrossui4, libkhtml5, libktexteditor4, libthreadweaver4