[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-14744Date: (C)2019-08-08   (M)2023-12-22


In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.8CVSS Score : 5.1
Exploit Score: 1.8Exploit Score: 4.9
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: HIGH
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
https://seclists.org/bugtraq/2019/Aug/9
https://seclists.org/bugtraq/2019/Aug/12
DSA-4494
FEDORA-2019-39d23c7a94
FEDORA-2019-48b691092f
FEDORA-2019-9f2ee52c88
FEDORA-2019-a746ac9c89
FEDORA-2019-f9f78895c3
GLSA-201908-07
RHSA-2019:2606
USN-4100-1
https://lists.debian.org/debian-lts-announce/2019/08/msg00023.html
http://packetstormsecurity.com/files/153981/Slackware-Security-Advisory-kdelibs-Updates.html
https://gist.githubusercontent.com/zeropwn/630832df151029cb8f22d5b6b9efaefb/raw/64aa3d30279acb207f787ce9c135eefd5e52643b/kde-kdesktopfile-command-injection.txt
https://www.zdnet.com/article/unpatched-kde-vulnerability-disclosed-on-twitter/
openSUSE-SU-2019:1851
openSUSE-SU-2019:1855
openSUSE-SU-2019:1898

CPE    5
cpe:/o:debian:debian_linux:9.0
cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
cpe:/o:redhat:enterprise_linux_server:7.0
cpe:/o:redhat:enterprise_linux_workstation:7.0
...
CWE    1
CWE-78
OVAL    13
oval:org.secpod.oval:def:116967
oval:org.secpod.oval:def:116961
oval:org.secpod.oval:def:116991
oval:org.secpod.oval:def:116990
...

© SecPod Technologies