Updated kconfig packages fix security vulnerability
Publication date: 15 Sep 2019Modification date: 15 Sep 2019
Type: security
Affected Mageia releases : 6 , 7
CVE: CVE-2019-14744
Description
Updated kconfig packages fix security vulnerability: Dominik Penner discovered that KConfig supported a feature to define shell command execution in .desktop files. If a user is provided with a malformed .desktop file (e.g. if it's embedded into a downloaded archive and it gets opened in a file browser) arbitrary commands could get executed (CVE-2019-14744). This update fixes the security issue by removing the shell command feature.
References
SRPMS
6/core
- kconfig-5.42.0-1.1.mga6
7/core
- kconfig-5.57.0-1.1.mga7