VulnerabilityModified
CVE-2019-14744
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction.
HIGH 7.8EPSS 4.07%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 4.07% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- kde/kconfig · debian/debian linux · fedoraproject/fedora · opensuse/backports sle · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00013.htmlMailing List, Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00016.htmlMailing List, Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00034.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/153981/Slackware-Security-Advisory-kdelibs-Updates.htmlPatch, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2606Third Party Advisory
- https://gist.githubusercontent.com/zeropwn/630832df151029cb8f22d5b6b9efaefb/raw/64aa3d30279acb207f787ce9c135eefd5e52643b/kde-kdesktopfile-command-injection.txtExploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00023.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5IRIKH7ZWXELIQT6WSLV7EG3VTFWKZPD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNHO6FZRYBQ2R3UCFDGS66F6DNNTKCMM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UYKLUSSEK3YJOVQDL6K2LKGS3354UH6L/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTFBQRJAU7ITD3TOMPZAUQMYYCAZ6DTX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YIDXQ6CUB5E7Y3MJWCUY4VR42QAE6SCJ/
- https://seclists.org/bugtraq/2019/Aug/12Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/9Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201908-07Third Party Advisory
- https://usn.ubuntu.com/4100-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4494Third Party Advisory
- https://www.zdnet.com/article/unpatched-kde-vulnerability-disclosed-on-twitter/Press/Media Coverage, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00013.htmlMailing List, Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00016.htmlMailing List, Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00034.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/153981/Slackware-Security-Advisory-kdelibs-Updates.htmlPatch, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2606Third Party Advisory
- https://gist.githubusercontent.com/zeropwn/630832df151029cb8f22d5b6b9efaefb/raw/64aa3d30279acb207f787ce9c135eefd5e52643b/kde-kdesktopfile-command-injection.txtExploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00023.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5IRIKH7ZWXELIQT6WSLV7EG3VTFWKZPD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNHO6FZRYBQ2R3UCFDGS66F6DNNTKCMM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UYKLUSSEK3YJOVQDL6K2LKGS3354UH6L/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTFBQRJAU7ITD3TOMPZAUQMYYCAZ6DTX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YIDXQ6CUB5E7Y3MJWCUY4VR42QAE6SCJ/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.