CVE-2019-14744: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 4.1% chance of exploitation in the next 30 days.

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only
  • Kde Kconfig: before 5.61.0 (fixed in 5.61.0)
  • Opensuse Backports Sle: version 15.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2019-08-07. Last modified 2026-06-17.