Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-14744

Опубликовано: 07 авг. 2019
Источник: nvd
CVSS3: 7.8
CVSS2: 5.1
EPSS Низкий

Описание

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kde:kconfig:*:*:*:*:*:*:*:*
Версия до 5.61.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
Конфигурация 5

Одно из

cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
Конфигурация 6

Одно из

cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.04069
Низкий

7.8 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

CVSS3: 8.8
redhat
почти 7 лет назад

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

CVSS3: 7.8
debian
почти 7 лет назад

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and c ...

suse-cvrf
почти 7 лет назад

Security update for kconfig, kdelibs4

suse-cvrf
почти 7 лет назад

Security update for kconfig, kdelibs4

EPSS

Процентиль: 90%
0.04069
Низкий

7.8 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-78