Skip to content

Commit

Permalink
security/vuxml: Document plasma[56]-plasma-workspace vuln
Browse files Browse the repository at this point in the history
  • Loading branch information
BSDKaffee committed Jun 12, 2024
1 parent 61b47bb commit 7dd32fa
Showing 1 changed file with 35 additions and 0 deletions.
35 changes: 35 additions & 0 deletions security/vuxml/vuln/2024.xml
Original file line number Diff line number Diff line change
@@ -1,3 +1,38 @@
<vuln vid="479df73e-2838-11ef-9cab-4ccc6adda413">
<topic>plasma[56]-plasma-workspace -- Unauthorized users can access session manager</topic>
<affects>
<package>
<name>plasma5-plasma-workspace</name>
<range><lt>5.27.11.1</lt></range>
</package>
<package>
<name>plasma6-plasma-workspace</name>
<range><lt>6.0.4_2</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>David Edmundson reports:</p>
<blockquote cite="https://kde.org/info/security/advisory-20240531-1.txt">
<p>KSmserver, KDE's XSMP manager, incorrectly allows connections via ICE
based purely on the host, allowing all local connections. This allows
another user on the same machine to gain access to the session
manager.</p>
<p>A well crafted client could use the session restore feature to execute
arbitrary code as the user on the next boot.</p>
</blockquote>
</body>
</description>
<references>
<cvename>CVE-2024-36041</cvename>
<url>https://kde.org/info/security/advisory-20240531-1.txt</url>
</references>
<dates>
<discovery>2024-05-31</discovery>
<entry>2024-06-11</entry>
</dates>
</vuln>

<vuln vid="5f608c68-276c-11ef-8caa-0897988a1c07">
<topic>Composer -- Multiple command injections via malicious git/hg branch names</topic>
<affects>
Expand Down

0 comments on commit 7dd32fa

Please sign in to comment.