OS Command Injection in KDE Frameworks - CVE-2019-14744
Published: August 7, 2019 / Updated: August 7, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing .desktop and .directory files within the KConfigGroup::readEntry() function. A remote attacker can create a specially crafted file or folder, trick the user into opening it and execute arbitrary OS commands with privileges of the current user.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Examples:
1) payload.desktop
[Desktop Entry]
Icon[$e]=$(echo${IFS}0>~/Desktop/zero.lol&)
2) .directory
[Desktop Entry]
Type=Directory
Icon[$e]=$(echo${IFS}0>~/Desktop/zero.lol&) Affected software
Gentoo Linux
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Slackware Linux
SUSE Linux
Opensuse
openEuler
kdelibs (Red Hat package)
kde4libs (Ubuntu package)
kconfig (Ubuntu package)
kconfig (Debian package)
kconfig (Alpine package)
attica (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
kdelibs3
kdelibs
kf5-kconfig
kf5-kconfig-devel
kf5-kconfig-debuginfo
kf5-kconfig-debugsource
kf5-kconfig-core
kf5-kconfig-gui
kde-settings
SUSE Package Hub for SUSE Linux Enterprise
How to mitigate CVE-2019-14744
kdelibs (Red Hat package) - update to 4.14.8-8.el7_6
kde4libs (Ubuntu package) - addressed in versions 4:4.14.16-0ubuntu3.3, 4:4.14.38-0ubuntu3.1, 4:4.14.38-0ubuntu6.1
kconfig (Ubuntu package) - addressed in versions 5.18.0-0ubuntu1.1, 5.44.0-0ubuntu1.1, 5.56.0-0ubuntu1.1
kconfig (Debian package) - addressed in versions 5.28.0-2+deb9u1, 5.54.0-1+deb10u1
kconfig (Alpine package) - update to 5.60.0-r1
attica (Alpine package) - update to 5.61.0-r0
kdelibs3 - addressed in versions 3.5.10-101.fc29, 3.5.10-101.fc30
kdelibs - addressed in versions 4.14.38-15.fc29, 4.14.38-15.fc30
kf5-kconfig - addressed in versions 5.52.0-1.el7.1, 5.59.0-1.fc30.1
kf5-kconfig-devel - update to 5.55.0-3
kf5-kconfig-debuginfo - update to 5.55.0-3
kf5-kconfig-debugsource - update to 5.55.0-3
kf5-kconfig-core - update to 5.55.0-3
kf5-kconfig-gui - update to 5.55.0-3
kf5-kconfig - update to 5.55.0-3
kde-settings - addressed in versions 29.1-1.fc29, 30.3-1.fc30
External References
Related Security Bulletins
- Remote code execution in KDE
- Slackware Linux update for kdelibs
- Debian update for kconfig
- OpenSUSE Linux update for kconfig, kdelibs4
- OpenSUSE Linux update for kconfig, kdelibs4
- OpenSUSE Linux update for kconfig, kdelibs4
- OpenSUSE Linux update for kconfig, kdelibs4
- OpenSUSE Linux update for kconfig, kdelibs4
- Ubuntu update for KConfig and KDE libraries
- Gentoo update for KDE KConfig
- Red Hat update for kdelibs and kde-settings
- Red Hat Enterprise Linux 7 update for kdelibs
- OS Command Injection in attica (Alpine package)
- OS Command Injection in kconfig (Alpine package)
- openEuler 20.03 LTS SP1 update for kf5-kconfig
- Fedora 30 update for kf5-kconfig
- Fedora EPEL 7 update for kf5-kconfig
- Fedora 29 update for kdelibs3
- Fedora 30 update for kdelibs3
- Fedora 29 update for kde-settings, kdelibs
- Fedora 30 update for kde-settings, kdelibs