DEBIAN-CVE-2019-14744

Source
https://security-tracker.debian.org/tracker/CVE-2019-14744
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2019-14744.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2019-14744
Upstream
Published
2019-08-07T15:15:13.970Z
Modified
2025-11-14T04:01:09.374471Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

References

Affected packages

Debian:11 / kconfig

Package

Name
kconfig
Purl
pkg:deb/debian/kconfig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.54.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / kconfig

Package

Name
kconfig
Purl
pkg:deb/debian/kconfig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.54.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / kconfig

Package

Name
kconfig
Purl
pkg:deb/debian/kconfig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.54.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / kconfig

Package

Name
kconfig
Purl
pkg:deb/debian/kconfig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.54.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}