External Initialization of Trusted Variables or Data Stores Affecting kdelibs-apidocs package, versions *


Severity

Recommended
0.0
high
0
10

Based on CentOS security rating.

Threat Intelligence

EPSS
0.39% (74th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS6-KDELIBSAPIDOCS-2003775
  • published26 Jul 2021
  • disclosed12 Aug 2019

Introduced: 12 Aug 2019

CVE-2019-14744  (opens in a new tab)
CWE-454  (opens in a new tab)

How to fix?

There is no fixed version for Centos:6 kdelibs-apidocs.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kdelibs-apidocs package and not the kdelibs-apidocs package as distributed by Centos. See How to fix? for Centos:6 relevant fixed versions and status.

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

References

CVSS Scores

version 3.1