| Summary: | kde-plasma/plasma-workspace: two vulnerabilities (CVE-2015-1308) | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED FIXED | ||
| Severity: | minor | ||
| Priority: | Normal | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | B3 [noglsa cve] | ||
| Package list: | Runtime testing required: | --- | |
|
Description
Agostino Sarubbo
2015-01-19 15:36:31 UTC
Only the second issue affects packages in the tree, and I do not expect any patch to be provided by upstream. CVE-2015-1308 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1308): kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked. This has been gone from the tree for quite some time. GLSA Vote: No Plasma 4 removed from tree. https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7f71cc2968e08d586ccd24ad34c34230ddf37f62 Repository is clean, all done. |