FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

KDE Frameworks -- malicious .desktop files execute code

Affected packages
kf5-kconfig < 5.60.0_2

Details

VuXML ID f5f0a640-bae8-11e9-bb3a-001e2a3f778d
Discovery 2019-08-07
Entry 2019-08-09

The KDE Community has released a security announcement:

The syntax Key[$e]=$(shell command) in *.desktop files, .directory files, and configuration files (typically found in ~/.config) was an intentional feature of KConfig, to allow flexible configuration. This could however be abused by malicious people to make the users install such files and get code executed even without intentional action by the user.

References

CVE Name CVE-2019-14744
URL https://kde.org/info/security/advisory-20190807-1.txt