KDE4/5 Zero-Day Vulnerability Alert!

Brad R Wednesday 07 August 2019 - 15:08:35  

This is a serious vulnerability, if you're using KDE4 or KDE5:

Zero-Day Bug in KDE 4/5 Executes Commands by Opening a Folder

An unpatched zero-day vulnerability exists in KDE 4 & 5 that could allow attackers to execute code simply by tricking a user into downloading an archive, extracting it, and then opening the folder.

...According to Penner, this vulnerability exists in KDE version 4 and 5 and allows commands embedded in .desktop and .directory files to be executed simply by opening a folder, or in some cases, extracting an archive to the desktop.


Read the whole thing. No fix is yet available, so be careful with your downloads. Or switch to a different desktop manager.
printer friendly

You must be logged in to make comments on this site - please log in, or if you are not registered click here to signup