Improper handling of unicode string terminator in kdesu invocation could lead to unintended code execution. PoC: echo Hi@; whoami > /tmp/filebyroot If @ is the unicode string terminator, it would only tell the user that kdesu executed "echo Hi" but it also creates the /tmp/filebyroot file as root Upstream patch: https://github.com/KDE/kde-cli-tools/commit/5eda179a099ba68a20dc21dc0da63e85a565a171 CVE assignment: http://seclists.org/oss-sec/2016/q3/653
Created kf5-kdesu tracking bugs for this issue: Affects: fedora-all [bug 1380387] Affects: epel-7 [bug 1380388]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.