High severity8.1NVD Advisory· Published May 7, 2019· Updated Jun 17, 2026
CVE-2019-7443
CVE-2019-7443
Description
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
28cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
- KDE/KAuthdescription
- osv-coords20 versionspkg:rpm/opensuse/extra-cmake-modules&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/kauth&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/kcoreaddons&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/polkit-qt5-1&distro=openSUSE%20Leap%2015.0pkg:rpm/suse/extra-cmake-modules&distro=SUSE%20Package%20Hub%2012%20SP1pkg:rpm/suse/extra-cmake-modules&distro=SUSE%20Package%20Hub%2012%20SP2pkg:rpm/suse/extra-cmake-modules&distro=SUSE%20Package%20Hub%2012%20SP3pkg:rpm/suse/extra-cmake-modules&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/kauth&distro=SUSE%20Package%20Hub%2012%20SP1pkg:rpm/suse/kauth&distro=SUSE%20Package%20Hub%2012%20SP2pkg:rpm/suse/kauth&distro=SUSE%20Package%20Hub%2012%20SP3pkg:rpm/suse/kauth&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/kcoreaddons&distro=SUSE%20Package%20Hub%2012%20SP1pkg:rpm/suse/kcoreaddons&distro=SUSE%20Package%20Hub%2012%20SP2pkg:rpm/suse/kcoreaddons&distro=SUSE%20Package%20Hub%2012%20SP3pkg:rpm/suse/kcoreaddons&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/polkit-qt5-1&distro=SUSE%20Package%20Hub%2012%20SP1pkg:rpm/suse/polkit-qt5-1&distro=SUSE%20Package%20Hub%2012%20SP2pkg:rpm/suse/polkit-qt5-1&distro=SUSE%20Package%20Hub%2012%20SP3pkg:rpm/suse/polkit-qt5-1&distro=SUSE%20Package%20Hub%2015
< 5.32.0-7.2+ 19 more
- (no CPE)range: < 5.32.0-7.2
- (no CPE)range: < 5.45.0-bp150.5.2
- (no CPE)range: < 5.45.0-bp150.3.6.2
- (no CPE)range: < 0.112.0-5.2
- (no CPE)range: < 5.32.0-7.2
- (no CPE)range: < 5.32.0-7.2
- (no CPE)range: < 5.32.0-7.2
- (no CPE)range: < 5.32.0-7.2
- (no CPE)range: < 5.45.0-bp150.5.2
- (no CPE)range: < 5.45.0-bp150.5.2
- (no CPE)range: < 5.45.0-bp150.5.2
- (no CPE)range: < 5.45.0-bp150.5.2
- (no CPE)range: < 5.45.0-bp150.3.6.2
- (no CPE)range: < 5.45.0-bp150.3.6.2
- (no CPE)range: < 5.45.0-bp150.3.6.2
- (no CPE)range: < 5.45.0-bp150.3.6.2
- (no CPE)range: < 0.112.0-5.2
- (no CPE)range: < 0.112.0-5.2
- (no CPE)range: < 0.112.0-5.2
- (no CPE)range: < 0.112.0-5.2
Patches
Vulnerability mechanics
References
6- bugzilla.suse.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- cgit.kde.org/kauth.git/commit/nvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2019-02/msg00060.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-02/msg00065.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAWLQKTUQJOAPXOFWJQAQCA4LVM2P45F/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PXVUJNXB6QKGPT6YJPJSG3U2BIR5XK5Y/nvd
News mentions
0No linked articles in our index yet.