CVE-2019-14744

HIGH

KDE Kconfig < 5.61.0 - OS Command Injection

Title source: rule

Description

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

References (18)

Scores

CVSS v3 7.8
EPSS 0.0131
EPSS Percentile 79.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-78
Status published

Affected Products (12)

kde/kconfig < 5.61.0
debian/debian_linux
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
opensuse/backports_sle
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_workstation

Timeline

Published Aug 07, 2019
Tracked Since Feb 18, 2026