CVE-2019-7443: Input Validation
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-7443.
What is the severity level of CVE-2019-7443?
CVE-2019-7443 has a severity level of critical (8.1).
How does CVE-2019-7443 affect KDE KAuth?
CVE-2019-7443 affects KDE KAuth versions up to and excluding 5.55.0.
How can this vulnerability be exploited?
This vulnerability can be exploited by passing parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp.
Are there any known fixes for CVE-2019-7443?
Yes, updating KDE KAuth to version 5.55.0 or higher is the recommended fix for this vulnerability.