An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
Created plasma-workspace tracking bugs for this issue:
Affects: fedora-all [bug 1543471]
This issue did not affect the versions of kdebase-runtime as shipped with Red Hat Enterprise Linux 6. This issue did not affect the versions of kde-runtime as shipped with Red Hat Enterprise Linux 7.