CVE-2018-6791
published 2018-02-07CVE-2018-6791: An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its…
PriorityP430medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
EPSS
0.78%
52.2th percentile
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | plasma-workspace | < plasma-workspace 4:5.12.0-2 (bookworm) | plasma-workspace 4:5.12.0-2 (bookworm) |
| kde | plasma-workspace | < 5.12.0 | 5.12.0 |
| kde | plasma-workspace | >= 0 < 4:5.12.0-2 | 4:5.12.0-2 |
| kde | plasma-workspace | >= 0 < 4:5.12.0-2 | 4:5.12.0-2 |
| kde | plasma-workspace | >= 0 < 4:5.12.0-2 | 4:5.12.0-2 |
| kde | plasma-workspace | >= 0 < 4:5.12.0-2 | 4:5.12.0-2 |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wfc7-x8jc-jx99: An issue was discovered in soliduiserver/deviceserviceaction
ghsa_unreviewed·2022-05-13
CVE-2018-6791 [HIGH] CWE-78 GHSA-wfc7-x8jc-jx99: An issue was discovered in soliduiserver/deviceserviceaction
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
OSV
CVE-2018-6791: An issue was discovered in soliduiserver/deviceserviceaction
osv·2018-02-07·CVSS 6.8
CVE-2018-6791 [MEDIUM] CVE-2018-6791: An issue was discovered in soliduiserver/deviceserviceaction
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
Red Hat
kde-runtime: Arbitrary command execution in the removable device notifier
vendor_redhat·2018-02-08·CVSS 6.8
CVE-2018-6791 [MEDIUM] CWE-138 kde-runtime: Arbitrary command execution in the removable device notifier
kde-runtime: Arbitrary command execution in the removable device notifier
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
Statement: This issue did not affect the versions of kdebase-runtime as shipped with Red Hat Enterprise Linux 6. This issue did not affect the versions of kde-runtime as shipped with Red Hat Enterprise Linux 7.
Package: kdebase-runtime (Red Hat Enterprise Linux 6) - Not affected
Package: k
Debian
CVE-2018-6791: plasma-workspace - An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma W...
vendor_debian·2018·CVSS 6.8
CVE-2018-6791 [MEDIUM] CVE-2018-6791: plasma-workspace - An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma W...
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
Scope: local
bookworm: resolved (fixed in 4:5.12.0-2)
bullseye: resolved (fixed in 4:5.12.0-2)
forky: resolved (fixed in 4:5.12.0-2)
sid: resolved (fixed in 4:5.12.0-2)
trixie: resolved (fixed in 4:5.12.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-6790 CVE-2018-6791 plasma-workspace: various flaws [fedora-all]
bugzilla·2018-02-08·CVSS 5.3
CVE-2018-6790 [MEDIUM] CVE-2018-6790 CVE-2018-6791 plasma-workspace: various flaws [fedora-all]
CVE-2018-6790 CVE-2018-6791 plasma-workspace: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2018-6791 kde-runtime: Arbitrary command execution in the removable device notifier
bugzilla·2018-02-08·CVSS 6.8
CVE-2018-6791 [MEDIUM] CVE-2018-6791 kde-runtime: Arbitrary command execution in the removable device notifier
CVE-2018-6791 kde-runtime: Arbitrary command execution in the removable device notifier
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
External References:
https://www.kde.org/info/security/advisory-20180208-2.txt
Discussion:
Created plasma-workspace tracking bugs for this issue:
Affects: fedora-all [bug 1543471]
---
Upstream commits:
Plasma 5.8:
https://commits.kde.org/plasma-workspace/9db872df82c25831
arXiv
BeatCoin: Leaking Private Keys from Air-Gapped Cryptocurrency Wallets
arxiv_fulltext·2018-04-23
BeatCoin: Leaking Private Keys from Air-Gapped Cryptocurrency Wallets
BeatCoin: Leaking Private Keys from Air-Gapped Cryptocurrency Wallets
Dr. Mordechai Guri
Ben-Gurion University of the Negev, Israel\ -Security Research Center
[email protected]\ video (1): https://youtu.be/2WtiHZNeveY\ video (2): https://youtu.be/ddmHOvT866o
## Abstract
Cryptocurrency wallets store the wallet’s private key(s), and hence, are a lucrative target for attackers. With possession of the private key, an attacker virtually owns all of the currency in the compromised wallet. Managing cryptocurrency wallets offline, in isolated ('air-gapped') computers, has been suggested in order to secure the private keys from theft. Such air-gapped wallets are often referred to as 'cold wallets.'
In this paper we show how private keys can be exfiltrated from air-gapped wallets. In the adv
https://bugs.kde.org/show_bug.cgi?id=389815https://cgit.kde.org/plasma-workspace.git/commit/?id=9db872df82c258315c6ebad800af59e81ffb9212https://www.debian.org/security/2018/dsa-4116https://bugs.kde.org/show_bug.cgi?id=389815https://cgit.kde.org/plasma-workspace.git/commit/?id=9db872df82c258315c6ebad800af59e81ffb9212https://www.debian.org/security/2018/dsa-4116
2018-02-07
Published