PT-2018-17747 · Kde+2 · Kde Plasma Workspace+2

Krzysztof Sieluzycki

·

Published

2018-02-07

·

Updated

2024-06-17

·

CVE-2018-6791

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions KDE Plasma Workspace versions prior to 5.12.0
Description An issue was discovered in the device service action of KDE Plasma Workspace. When a vfat thumbdrive with a volume label containing `` or $() is plugged in and mounted, it is interpreted as a shell command. This can lead to arbitrary command execution. For example, a volume label like "$(touch b)" can create a file called b in the home folder.
Recommendations For versions prior to 5.12.0, update to version 5.12.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the device notifier to mount vfat thumbdrives with potentially malicious volume labels until a patch is applied. Restrict access to the device notifier to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1172
ALT-PU-2018-2403
ALT-PU-2024-8795
CVE-2018-6791
DSA-4116-1
OPENSUSE-SU-2018:0397-1
OPENSUSE-SU-2018:0398-1
OPENSUSE-SU-2018_0397-1

Affected Products

Alt Linux
Kde Plasma Workspace
Suse