CVE-2019-14744OS Command Injection in Kconfig

Severity
7.8HIGHNVD
OSV7.5
EPSS
1.3%
top 20.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 7
Latest updateMay 24

Description

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

Also affects: Debian Linux 10.0, 9.0, Fedora 29, 30, Ubuntu Linux 16.04, 18.04, 19.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-7r6x-j8mj-9g3p: In KDE Frameworks KConfig before 52022-05-24
OSV
kconfig, kde4libs vulnerabilities2019-08-16
OSV
CVE-2019-14744: In KDE Frameworks KConfig before 52019-08-07
CVEList
CVE-2019-14744: In KDE Frameworks KConfig before 52019-08-07

📋Vendor Advisories

3
Ubuntu
KConfig and KDE libraries vulnerabilities2019-08-16
Red Hat
kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction2019-08-12
Debian
CVE-2019-14744: kconfig - In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configurati...2019

💬Community

3
Bugzilla
CVE-2019-14744 kdelibs3: kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction [epel-7]2019-08-12
Bugzilla
CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction2019-08-12
Bugzilla
CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction [fedora-all]2019-08-12
CVE-2019-14744 — OS Command Injection in KDE Kconfig | cvebase