Advisories ยป MGASA-2019-0278

Updated kconfig packages fix security vulnerability

Publication date: 15 Sep 2019
Modification date: 15 Sep 2019
Type: security
Affected Mageia releases : 6 , 7
CVE: CVE-2019-14744

Description

Updated kconfig packages fix security vulnerability:

Dominik Penner discovered that KConfig supported a feature to define shell
command execution in .desktop files. If a user is provided with a malformed
.desktop file (e.g. if it's embedded into a downloaded archive and it gets
opened in a file browser) arbitrary commands could get executed
(CVE-2019-14744).

This update fixes the security issue by removing the shell command feature.
                

References

SRPMS

6/core

7/core