CVE-2018-6791: OS Command Injection
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/kde-runtimeto a version that resolves this vulnerability.Fixed in 4:17.08.3-2.1 - Upgrade
Upgrade
debian/plasma-workspaceto a version that resolves this vulnerability.Fixed in 4:5.14.5.1-1Fixed in 4:5.20.5-6Fixed in 4:5.27.5-2+deb12u1Fixed in 4:5.27.8-2
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-6791.
What is the severity of CVE-2018-6791?
The severity of CVE-2018-6791 is high with a score of 6.8.
Which software versions are affected by CVE-2018-6791?
CVE-2018-6791 affects KDE Plasma Workspace versions before 5.12.0 and kde-runtime version 4:17.08.3-2.1.
How can I fix the vulnerability identified in CVE-2018-6791?
To fix the vulnerability, update to KDE Plasma Workspace 5.12.0 or later and kde-runtime version 4:17.08.3-2.1.
Where can I find more information about CVE-2018-6791?
You can find more information about CVE-2018-6791 at the following references: [Link 1](https://bugs.kde.org/show_bug.cgi?id=389815), [Link 2](https://cgit.kde.org/plasma-workspace.git/commit/?id=9db872df82c258315c6ebad800af59e81ffb9212), [Link 3](https://www.debian.org/security/2018/dsa-4116).