REDHAT-BUG-2371635: High severity KDE Konsole vulnerability
KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this mode, there is a code path where if that binary is not available, Konsole falls back to using /bin/bash for the given arguments (i.e., the URL) provided. This allows an attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2371635?
REDHAT-BUG-2371635 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix REDHAT-BUG-2371635?
To fix REDHAT-BUG-2371635, upgrade KDE Konsole to version 25.04.2 or later.
What software is affected by REDHAT-BUG-2371635?
KDE Konsole versions prior to 25.04.2 are affected by REDHAT-BUG-2371635.
Is remote code execution possible with REDHAT-BUG-2371635?
Yes, REDHAT-BUG-2371635 allows for remote code execution through specific URL scheme handlers.
When was REDHAT-BUG-2371635 disclosed?
REDHAT-BUG-2371635 was disclosed prior to the release of the affected software version 25.04.2.