ZeroHour

CVE-2019-14744

PoC
CVSS 3.1
7.8 high
EPSS
4%p90
Published
()
Modified
Description

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

Vendors
kdedebianfedoraprojectopensusecanonicalredhat
Products
kconfig, debian linux, fedora, backports sle, ubuntu linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.