CVE-2019-14744
HIGHKDE Kconfig < 5.61.0 - OS Command Injection
Title source: ruleDescription
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
References (18)
Scores
CVSS v3
7.8
EPSS
0.0131
EPSS Percentile
79.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-78
Status
published
Affected Products (12)
kde/kconfig
< 5.61.0
debian/debian_linux
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
opensuse/backports_sle
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_workstation
Timeline
Published
Aug 07, 2019
Tracked Since
Feb 18, 2026