{"id":"openSUSE-SU-2018:0397-1","summary":"Security update for plasma5-workspace","details":"This update for plasma5-workspace fixes security issues and bugs.\n\nThe following vulnerabilities were fixed:\n\n- CVE-2018-6790: Desktop notifications could have been used to load arbitrary remote images into Plasma,\n                 allowing for client IP discovery (boo#1079429)\n- CVE-2018-6791: A specially crafted file system label may have allowed execution of arbitrary code (boo#1079751)\n\nThe following bugs were fixed:\n\n- Plasma could freeze with certain notifications (boo#1013550)\n","modified":"2026-02-04T04:37:12.804529Z","published":"2018-02-08T08:16:14Z","related":["CVE-2018-6790","CVE-2018-6791"],"upstream":["CVE-2018-6790","CVE-2018-6791"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BT2QPNOSYGV4PRT6334ZOQQEDV2F6DFL/#BT2QPNOSYGV4PRT6334ZOQQEDV2F6DFL"},{"type":"REPORT","url":"https://bugzilla.suse.com/1013550"},{"type":"REPORT","url":"https://bugzilla.suse.com/1079429"},{"type":"REPORT","url":"https://bugzilla.suse.com/1079751"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6790"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-6791"}],"affected":[{"package":{"name":"plasma5-workspace","ecosystem":"SUSE:Package Hub 12 SP3","purl":"pkg:rpm/suse/plasma5-workspace&distro=SUSE%20Package%20Hub%2012%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.8.7-8.1"}]}],"ecosystem_specific":{"binaries":[{"drkonqi5":"5.8.7-8.1","plasma5-workspace-devel":"5.8.7-8.1","plasma5-workspace-lang":"5.8.7-8.1","plasma5-workspace-libs":"5.8.7-8.1","plasma5-workspace":"5.8.7-8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2018:0397-1.json"}}],"schema_version":"1.7.3"}