PT-2018-17747 · Kde+2 · Kde Plasma Workspace+2

Krzysztof Sieluzycki

·

Publicado

2018-02-07

·

Atualizado

2024-06-17

·

CVE-2018-6791

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions KDE Plasma Workspace versions prior to 5.12.0
Description An issue was discovered in the device service action of KDE Plasma Workspace. When a vfat thumbdrive with a volume label containing `` or $() is plugged in and mounted, it is interpreted as a shell command. This can lead to arbitrary command execution. For example, a volume label like "$(touch b)" can create a file called b in the home folder.
Recommendations For versions prior to 5.12.0, update to version 5.12.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the device notifier to mount vfat thumbdrives with potentially malicious volume labels until a patch is applied. Restrict access to the device notifier to minimize the risk of exploitation.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1172
ALT-PU-2018-2403
ALT-PU-2024-8795
CVE-2018-6791
DSA-4116-1
OPENSUSE-SU-2018:0397-1
OPENSUSE-SU-2018:0398-1
OPENSUSE-SU-2018_0397-1

Produtos afetados

Alt Linux
Kde Plasma Workspace
Suse