USN-8856-1: Kdenlive, MLT vulnerability
AI summary · grok-4.7
Ubuntu’s USN-8856-1 fixes a Kdenlive flaw letting malicious project files run commands via MLT.
Ubuntu published USN-8856-1 covering Kdenlive and the MLT multimedia framework. Kdenlive accepted dangerous proxy parameters when processing attacker-controlled project files. An attacker could execute arbitrary commands through the MLT framework's ante and post consumer properties. The notice does not name a CVE or report exploitation in the wild.
- Malicious Kdenlive project files can pass dangerous proxy parameters.
- MLT ante and post consumer properties can execute arbitrary commands.
- The notice cites no CVE and does not report active exploitation.
Full article
It was discovered that Kdenlive allowed dangerous proxy parameters when processing attacker-controlled project files. An attacker could use this to execute arbitrary commands via the MLT framework's ante/post consumer properties.
This source does not provide full text. Read it at ubuntu.com.