CVE-2019-7443

NameCVE-2019-7443
DescriptionInsecure handling of arguments in helpers
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
Debian Bugs921995

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kauth (PTS)stretch5.28.0-2vulnerable
buster5.54.0-1vulnerable
sid5.54.0-2fixed
kde4libs (PTS)jessie (security), jessie4:4.14.2-5+deb8u2vulnerable
stretch4:4.14.26-2vulnerable
buster, sid4:4.14.38-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kauthsource(unstable)5.54.0-2921995
kde4libssource(unstable)(unfixed)

Notes

[stretch] - kauth <no-dsa> (Minor issue, will be fixed in a point release)
[stretch] - kde4libs <no-dsa> (Minor issue)
https://mail.kde.org/pipermail/kde-announce/2019-February/000011.html
https://cgit.kde.org/kauth.git/commit/?id=fc70fb0161c1b9144d26389434d34dd135cd3f4a

Search for package or bug name: Reporting problems