From ff64c164b3070caa6ec2bf19cbea6d9083251e93 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sat, 6 Jul 2024 06:45:04 +0000 Subject: [ GLSA 202407-20 ] KDE Plasma Workspaces: Privilege Escalation Bug: https://bugs.gentoo.org/933342 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202407-20.xml | 48 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 glsa-202407-20.xml diff --git a/glsa-202407-20.xml b/glsa-202407-20.xml new file mode 100644 index 00000000..84856ba8 --- /dev/null +++ b/glsa-202407-20.xml @@ -0,0 +1,48 @@ + + + + KDE Plasma Workspaces: Privilege Escalation + A vulnerability has been discovered in KDE Plasma Workspaces, which can lead to privilege escalation. + plasma-workspace + 2024-07-06 + 2024-07-06 + 933342 + remote + + + 5.27.11.1 + 5.27.11.1 + + + +

KDE Plasma workspace is a widget based desktop environment designed to be fast and efficient.

+
+ +

Multiple vulnerabilities have been discovered in KDE Plasma Workspaces. Please review the CVE identifiers referenced below for details.

+
+ +

KSmserver, KDE's XSMP manager, incorrectly allows connections via ICE +based purely on the host, allowing all local connections. This allows +another user on the same machine to gain access to the session +manager. + +A well crafted client could use the session restore feature to execute +arbitrary code as the user on the next boot.

+
+ +

There is no known workaround at this time.

+
+ +

All KDE Plasma Workspaces users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=kde-plasma/plasma-workspace-5.27.11.1" + +
+ + CVE-2024-36041 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad