CVE-2019-14744: OS Command Injection
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-14744?
CVE-2019-14744 is a vulnerability in KDE Frameworks KConfig that allows for code execution through malicious desktop files and configuration files.
What is the severity of CVE-2019-14744?
CVE-2019-14744 has a severity rating of 7.8, which is considered high.
How does CVE-2019-14744 work?
CVE-2019-14744 works by exploiting the mishandling of .desktop and .directory files in libKF5ConfigCore.so, allowing for code execution with minimal user interaction.
What is the remedy for CVE-2019-14744?
The remedy for CVE-2019-14744 is to update to KDE Frameworks KConfig version 5.61.0 or later.
Where can I find more information about CVE-2019-14744?
You can find more information about CVE-2019-14744 in the references provided: [link1], [link2], [link3].