Vulnerability Description
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kde | Kconfig | < 5.61.0 |
| Debian | Debian Linux | 9.0 |
| Fedoraproject | Fedora | 29 |
| Opensuse | Backports Sle | 15.0 |
| Canonical | Ubuntu Linux | 16.04 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00013.htmlMailing ListPatchThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00016.htmlMailing ListPatchThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00034.htmlMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/153981/Slackware-Security-Advisory-kdelibs-PatchThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:2606Third Party Advisory
- https://gist.githubusercontent.com/zeropwn/630832df151029cb8f22d5b6b9efaefb/raw/ExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00023.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://seclists.org/bugtraq/2019/Aug/12Mailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Aug/9Mailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201908-07Third Party Advisory
FAQ
What is CVE-2019-14744?
CVE-2019-14744 is a vulnerability with a CVSS score of 7.8 (HIGH). In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling ...
How severe is CVE-2019-14744?
CVE-2019-14744 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14744?
Check the references section above for vendor advisories and patch information. Affected products include: Kde Kconfig, Debian Debian Linux, Fedoraproject Fedora, Opensuse Backports Sle, Canonical Ubuntu Linux.