Описание
Security update for kdebase4-workspace
This update for kdebase4-workspace fixes the following issues:
- CVE-2014-8651: Privilege escalation via KDE Clock KCM helper when non-default polkit settings are used (bsc#904625)
The following non-security bugs were fixed:
- bsc#929718: Make kdm recognize an IPv6 localhost address as localhost
Список пакетов
SUSE Linux Enterprise Desktop 11 SP3
kde4-kgreeter-plugins-4.3.5-0.12.20.1
kdebase4-wallpapers-4.3.5-0.11.20.1
kdebase4-workspace-4.3.5-0.12.20.1
kdebase4-workspace-ksysguardd-4.3.5-0.12.20.1
kdm-4.3.5-0.12.20.1
kwin-4.3.5-0.12.20.1
SUSE Linux Enterprise Desktop 11 SP4
kde4-kgreeter-plugins-4.3.5-0.12.20.1
kdebase4-wallpapers-4.3.5-0.11.20.1
kdebase4-workspace-4.3.5-0.12.20.1
kdebase4-workspace-ksysguardd-4.3.5-0.12.20.1
kdm-4.3.5-0.12.20.1
kwin-4.3.5-0.12.20.1
SUSE Linux Enterprise Server 11 SP3
kde4-kgreeter-plugins-4.3.5-0.12.20.1
kdebase4-wallpapers-4.3.5-0.11.20.1
kdebase4-workspace-4.3.5-0.12.20.1
kdebase4-workspace-ksysguardd-4.3.5-0.12.20.1
kdm-4.3.5-0.12.20.1
kwin-4.3.5-0.12.20.1
SUSE Linux Enterprise Server 11 SP3-TERADATA
kde4-kgreeter-plugins-4.3.5-0.12.20.1
kdebase4-wallpapers-4.3.5-0.11.20.1
kdebase4-workspace-4.3.5-0.12.20.1
kdebase4-workspace-ksysguardd-4.3.5-0.12.20.1
kdm-4.3.5-0.12.20.1
kwin-4.3.5-0.12.20.1
SUSE Linux Enterprise Server 11 SP4
kde4-kgreeter-plugins-4.3.5-0.12.20.1
kdebase4-wallpapers-4.3.5-0.11.20.1
kdebase4-workspace-4.3.5-0.12.20.1
kdebase4-workspace-ksysguardd-4.3.5-0.12.20.1
kdm-4.3.5-0.12.20.1
kwin-4.3.5-0.12.20.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3
kde4-kgreeter-plugins-4.3.5-0.12.20.1
kdebase4-wallpapers-4.3.5-0.11.20.1
kdebase4-workspace-4.3.5-0.12.20.1
kdebase4-workspace-ksysguardd-4.3.5-0.12.20.1
kdm-4.3.5-0.12.20.1
kwin-4.3.5-0.12.20.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
kde4-kgreeter-plugins-4.3.5-0.12.20.1
kdebase4-wallpapers-4.3.5-0.11.20.1
kdebase4-workspace-4.3.5-0.12.20.1
kdebase4-workspace-ksysguardd-4.3.5-0.12.20.1
kdm-4.3.5-0.12.20.1
kwin-4.3.5-0.12.20.1
SUSE Linux Enterprise Software Development Kit 11 SP3
kdebase4-workspace-devel-4.3.5-0.12.20.1
SUSE Linux Enterprise Software Development Kit 11 SP4
kdebase4-workspace-devel-4.3.5-0.12.20.1
Ссылки
- Link for SUSE-SU-2016:0303-1
- E-Mail link for SUSE-SU-2016:0303-1
- SUSE Security Ratings
- SUSE Bug 904625
- SUSE Bug 929718
- SUSE CVE CVE-2014-8651 page
Описание
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.
Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:kde4-kgreeter-plugins-4.3.5-0.12.20.1
SUSE Linux Enterprise Desktop 11 SP3:kdebase4-wallpapers-4.3.5-0.11.20.1
SUSE Linux Enterprise Desktop 11 SP3:kdebase4-workspace-4.3.5-0.12.20.1
SUSE Linux Enterprise Desktop 11 SP3:kdebase4-workspace-ksysguardd-4.3.5-0.12.20.1
Ссылки
- CVE-2014-8651
- SUSE Bug 904625