FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-05-17 11:57:46 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
0baee383-356c-11e7-b9a9-50e549ebab6ckauth: Local privilege escalation

Albert Astals Cid reports:

KAuth contains a logic flaw in which the service invoking dbus is not properly checked. This allows spoofing the identity of the caller and with some carefully crafted calls can lead to gaining root from an unprivileged account.


Discovery 2017-05-10
Entry 2017-05-10
kdelibs
< 4.14.30_4

kf5-kauth
< 5.33.0_1

CVE-2017-8422
http://www.openwall.com/lists/oss-security/2017/05/10/3
https://www.kde.org/info/security/advisory-20170510-1.txt
f714d8ab-028e-11e7-8042-50e549ebab6ckio: Information Leak when accessing https when using a malicious PAC file

Albert Astals Cid reports:

Using a malicious PAC file, and then using exfiltration methods in the PAC function FindProxyForURL() enables the attacker to expose full https URLs.

This is a security issue since https URLs may contain sensitive information in the URL authentication part (user:password@host), and in the path and the query (e.g. access tokens).

This attack can be carried out remotely (over the LAN) since proxy settings allow "Detect Proxy Configuration Automatically". This setting uses WPAD to retrieve the PAC file, and an attacker who has access to the victim's LAN can interfere with the WPAD protocols (DHCP/DNS+HTTP) and inject his/her own malicious PAC instead of the legitimate one.


Discovery 2017-02-28
Entry 2017-03-11
kdelibs
< 4.14.29_10

kf5-kio
< 5.31.0_1

https://www.kde.org/info/security/advisory-20170228-1.txt
6f358f5a-c7ea-11de-a9f3-0030843d3802KDE -- multiple vulnerabilities

oCERT reports:

Ark input sanitization errors: The KDE archiving tool, Ark, performs insufficient validation which leads to specially crafted archive files, using unknown MIME types, to be rendered using a KHTML instance, this can trigger uncontrolled XMLHTTPRequests to remote sites.

IO Slaves input sanitization errors: KDE protocol handlers perform insufficient input validation, an attacker can craft malicious URI that would trigger JavaScript execution. Additionally the 'help://' protocol handler suffer from directory traversal. It should be noted that the scope of this issue is limited as the malicious URIs cannot be embedded in Internet hosted content.

KMail input sanitization errors: The KDE mail client, KMail, performs insufficient validation which leads to specially crafted email attachments, using unknown MIME types, to be rendered using a KHTML instance, this can trigger uncontrolled XMLHTTPRequests to remote sites.

The exploitation of these vulnerabilities is unlikely according to Portcullis and KDE but the execution of active content is nonetheless unexpected and might pose a threat.


Discovery 2009-10-30
Entry 2009-11-02
kdebase-runtime
ge 4.0.* lt 4.3.1_2

kdelibs
ge 4.0.* lt 4.3.1_5

http://www.ocert.org/advisories/ocert-2009-015.html
4472ab39-6c66-11e6-9ca5-50e549ebab6ckdelibs -- directory traversal vulnerability

David Faure reports:

A maliciously crafted archive (.zip or .tar.bz2) with "../" in the file paths could be offered for download via the KNewStuff framework (e.g. on www.kde-look.org), and upon extraction would install files anywhere in the user's home directory.


Discovery 2016-07-24
Entry 2016-08-27
kdelibs
< 4.14.10_7

CVE-2016-6232
https://www.kde.org/info/security/advisory-20160724-1.txt
2f90556f-18c6-11e4-9cc4-5453ed2e2b49kdelibs -- KAuth PID Reuse Flaw

Martin Sandsmark reports:

The KAuth framework uses polkit-1 API which tries to authenticate using the requestors PID. This is prone to PID reuse race conditions.

This potentially allows a malicious application to pose as another for authentication purposes when executing privileged actions.


Discovery 2014-07-30
Entry 2014-07-31
kdelibs
< 4.12.5_3

CVE-2014-5033
http://lists.kde.org/?l=kde-announce&m=140674898412923&w=2
6d21a287-fce0-11e0-a828-00235a5f2c9akdelibs4, rekonq -- input validation failure

KDE Security Advisory reports:

The default rendering type for a QLabel is QLabel::AutoText, which uses heuristics to determine whether to render the given content as plain text or rich text. KSSL and Rekonq did not properly force its QLabels to use QLabel::PlainText. As a result, if given a certificate containing rich text in its fields, they would render the rich text. Specifically, a certificate containing a common name (CN) that has a table element will cause the second line of the table to be displayed. This can allow spoofing of the certificate's common name.


Discovery 2011-10-03
Entry 2011-10-23
kdelibs
ge 4.0.* lt 4.7.2

rekonq
< 0.8.0

http://www.kde.org/info/security/advisory-20111003-1.txt
http://www.nth-dimension.org.uk/pub/NDSA20111003.txt.asc
CVE-2011-3365
CVE-2011-3366