An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
{ "binaries": [ { "binary_name": "libkworkspace5-5", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "libkworkspace5-5-dbgsym", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "libplasma-geolocation-interface5", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "libplasma-geolocation-interface5-dbgsym", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "libtaskmanager5", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "libtaskmanager5-dbgsym", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "libweather-ion7", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "libweather-ion7-dbgsym", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "plasma-workspace", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "plasma-workspace-dbg", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "plasma-workspace-dbgsym", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "plasma-workspace-dev", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "plasma-workspace-dev-dbgsym", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "plasma-workspace-wayland", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "plasma-workspace-wayland-dbgsym", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "sddm-theme-breeze", "binary_version": "4:5.5.5.2-0ubuntu1.1" }, { "binary_name": "sddm-theme-breeze-dbgsym", "binary_version": "4:5.5.5.2-0ubuntu1.1" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }
{ "binaries": [ { "binary_name": "libcolorcorrect5", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "libcolorcorrect5-dbgsym", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "libkworkspace5-5", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "libkworkspace5-5-dbgsym", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "libplasma-geolocation-interface5", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "libplasma-geolocation-interface5-dbgsym", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "libtaskmanager6", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "libtaskmanager6-dbgsym", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "libweather-ion7", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "libweather-ion7-dbgsym", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "plasma-workspace", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "plasma-workspace-dbgsym", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "plasma-workspace-dev", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "plasma-workspace-wayland", "binary_version": "4:5.12.1-0ubuntu1" }, { "binary_name": "sddm-theme-breeze", "binary_version": "4:5.12.1-0ubuntu1" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }