{"id":"MGASA-2019-0278","summary":"Updated kconfig packages fix security vulnerability","details":"Updated kconfig packages fix security vulnerability:\n\nDominik Penner discovered that KConfig supported a feature to define shell\ncommand execution in .desktop files. If a user is provided with a malformed\n.desktop file (e.g. if it's embedded into a downloaded archive and it gets\nopened in a file browser) arbitrary commands could get executed\n(CVE-2019-14744).\n\nThis update fixes the security issue by removing the shell command feature.\n","modified":"2026-04-16T04:41:47.522396343Z","published":"2019-09-15T14:45:31Z","upstream":["CVE-2019-14744"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0278.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=25250"},{"type":"ADVISORY","url":"https://kde.org/info/security/advisory-20190807-1.txt"},{"type":"WEB","url":"https://www.debian.org/security/2019/dsa-4494"}],"affected":[{"package":{"name":"kconfig","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/kconfig?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.42.0-1.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0278.json"}},{"package":{"name":"kconfig","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/kconfig?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.57.0-1.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0278.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}