openSUSE-SU-2018:0398-1
Dashboard / Vulnerabilities / openSUSE-SU-2018:0398-1
openSUSE-SU-2018:0398-1
Summary: Security update for plasma5-workspace
Details: This update for plasma5-workspace fixes security issues and bugs. The following vulnerabilities were fixed: - CVE-2018-6790: Desktop notifications could have been used to load arbitrary remote images into Plasma, allowing for client IP discovery (boo#1079429) - CVE-2018-6791: A specially crafted file system label may have allowed execution of arbitrary code (boo#1079751) The following bugs were fixed: - Plasma could freeze with certain notifications (boo#1013550)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/O3VUSIEN5D322MWR2YA7OFCLYROIOPRV/#O3VUSIEN5D322MWR2YA7OFCLYROIOPRV, https://bugzilla.suse.com/1013550, https://bugzilla.suse.com/1079429, https://bugzilla.suse.com/1079751, https://www.suse.com/security/cve/CVE-2018-6790, https://www.suse.com/security/cve/CVE-2018-6791
Affected packages
Package
Name: plasma5-workspace
Purl: pkg:rpm/suse/plasma5-workspace&distro=SUSE%20Package%20Hub%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
