kconfig and CVE-2019-14744

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



FYI, some background,

https://kde.org/info/security/advisory-20190807-1.txt

Upstream decided to disable/remove support for shell commands in kconfig.  
Fedora currently utilizes this feature for kde4 local localized user-dir 
support via kdeglobals snippet:

kde-profile/minimal/share/config/kdeglobals:

[Paths]
Desktop[$e]=$(xdg-user-dir DESKTOP)
Documents[$e]=$(xdg-user-dir DOCUMENTS)


Personally, now as this apparently only affects kde4 codepaths, I'm 
comfortable following upstream's approach as it at most affects only a small 
handful of applications still using kde4 libraries.

Thoughts?

-- Rex
_______________________________________________
kde mailing list -- kde@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to kde-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/kde@xxxxxxxxxxxxxxxxxxxxxxx




[Index of Archives]     [KDE Users]     [Fedora General Discussion]     [Older Fedora Users Mail]     [Fedora Advisory Board]     [Fedora Security]     [Fedora Maintainers]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [ATA RAID]     [Fedora Marketing]     [Fedora Mentors]     [Fedora Package Announce]     [Fedora Package Review]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Triage]     [Coolkey]     [Yum Users]     [Yosemite Forum]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]

  Powered by Linux