CVE-2019-7443
Last modified
CVE-2019-7443 is a vulnerability of currently unknown severity. KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. EPSS estimates a 2.35% chance of exploitation in the next 30 days.
Description
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kde | Kauth | < 5.55.0 |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 42.3 |
| Opensuse | Backports | All versions |
| Fedoraproject | Fedora | 28 |
| Fedoraproject | Fedora | 29 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00060.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00065.htmlMailing List, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1124863Issue Tracking, Patch, Third Party Advisory
- https://cgit.kde.org/kauth.git/commit/?id=fc70fb0161c1b9144d26389434d34dd135cd3f4aPatch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00060.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00065.htmlMailing List, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1124863Issue Tracking, Patch, Third Party Advisory
- https://cgit.kde.org/kauth.git/commit/?id=fc70fb0161c1b9144d26389434d34dd135cd3f4aPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-7443?
How severe is CVE-2019-7443?
How do I fix CVE-2019-7443?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-7437PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has …
- CVE-2019-7438cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS …
- CVE-2019-7439cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a…
- CVE-2019-7440JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and S…
- CVE-2019-7441cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout …
- CVE-2019-7442An XML external entity (XXE) vulnerability in the Password V…
- CVE-2019-7474A vulnerability in SonicWall SonicOS and SonicOSv, allow aut…6.5
- CVE-2019-7475A vulnerability in SonicWall SonicOS and SonicOSv with manag…9.8
- CVE-2019-7476A vulnerability in SonicWall Global Management System (GMS),…8.1
- CVE-2019-7477A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Ci…
- CVE-2019-7478A vulnerability in GMS allow unauthenticated user to SQL inj…9.8
- CVE-2019-7479A vulnerability in SonicOS allow authenticated read-only adm…7.2
Are you affected by CVE-2019-7443?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
