First published: Wed Feb 07 2018(Updated: )
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/kde-runtime | 4:17.08.3-2.1 | |
debian/plasma-workspace | 4:5.14.5.1-1 4:5.20.5-6 4:5.27.5-2+deb12u1 4:5.27.8-2 | |
Kde Plasma-workspace | <5.12.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-6791.
The severity of CVE-2018-6791 is high with a score of 6.8.
CVE-2018-6791 affects KDE Plasma Workspace versions before 5.12.0 and kde-runtime version 4:17.08.3-2.1.
To fix the vulnerability, update to KDE Plasma Workspace 5.12.0 or later and kde-runtime version 4:17.08.3-2.1.
You can find more information about CVE-2018-6791 at the following references: [Link 1](https://bugs.kde.org/show_bug.cgi?id=389815), [Link 2](https://cgit.kde.org/plasma-workspace.git/commit/?id=9db872df82c258315c6ebad800af59e81ffb9212), [Link 3](https://www.debian.org/security/2018/dsa-4116).