Bug#922727: CVE-2019-7443

2019-03-20 Thread Sandro Knauß
Hey, > Shall we cherrypick/backport the patch on our own, then or rather ignore it > given the vast majority of applications uses kf5 now? I would recommend to cherrypick/backport. I think the base hasn't changed a lot, so it will be easy to backport. Unfortunately we sill have several applicat

Bug#922727: CVE-2019-7443

2019-03-20 Thread Moritz Muehlenhoff
On Wed, Mar 20, 2019 at 12:13:56AM +0100, Sandro Knauß wrote: > Hey, > > > The security bug filed against kauth in #921995 also seems to affect > > kde4libs, the code is in kdecore/auth/backends/dbus/DBusHelperProxy.cpp? > > yes, it is likely, that also kde4libs is affected. kauth is KDE Framewor

Bug#922727: CVE-2019-7443

2019-03-19 Thread Sandro Knauß
Hey, > The security bug filed against kauth in #921995 also seems to affect > kde4libs, the code is in kdecore/auth/backends/dbus/DBusHelperProxy.cpp? yes, it is likely, that also kde4libs is affected. kauth is KDE Frameworks. As the birth of KDE Frameworks is a split of kdelibs. I think KDE do

Bug#922727: CVE-2019-7443

2019-02-19 Thread Moritz Muehlenhoff
Source: kde4libs Severity: important Tags: security The security bug filed against kauth in #921995 also seems to affect kde4libs, the code is in kdecore/auth/backends/dbus/DBusHelperProxy.cpp? Cheers, Moritz