CVE-2019-14744

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-14744
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14744.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-14744
Related
Published
2019-08-07T15:15:13Z
Modified
2024-09-18T01:00:20Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

References

Affected packages

Debian:11 / kconfig

Package

Name
kconfig
Purl
pkg:deb/debian/kconfig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.54.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / kconfig

Package

Name
kconfig
Purl
pkg:deb/debian/kconfig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.54.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / kconfig

Package

Name
kconfig
Purl
pkg:deb/debian/kconfig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.54.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}