[kde-freebsd] ports/162735: [patch] privilege escalation with x11/kde4-workspace and openpam

Raphael Kubo da Costa rakuco at FreeBSD.org
Fri Dec 9 00:20:11 UTC 2011


The following reply was made to PR ports/162735; it has been noted by GNATS.

From: Raphael Kubo da Costa <rakuco at FreeBSD.org>
To: bug-followup at FreeBSD.org
Cc: loox at e-shell.net
Subject: Re: ports/162735: [patch] privilege escalation with x11/kde4-workspace and openpam
Date: Thu, 08 Dec 2011 21:52:31 -0200

 Raphael Kubo da Costa <rakuco at FreeBSD.org> writes:
 
 > An update on this: it looks like security at kde.org had not been
 > contacted at any point, so I finally did that. After some mail
 > exchanges, Oswald Buddenhagen (current kcheckpass maintainer) and the
 > security folks dispute the claim that this is a kcheckpass
 > vulnerability (at most it is an affected application).
 >
 > Jeff Mitchell from the security team is currently disputing the assigned CVE [1].
 >
 > [1] http://article.gmane.org/gmane.comp.security.oss.general/6415


More information about the kde-freebsd mailing list