A user could sneak an unicode string terminator in the kdesu invocation, which could hide the fact that more commands could be executed (CVE-2016-7787).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0473.json"