Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.RC
  • Bug#1107672: konsole: CVE-2025-49091

    From Salvatore Bonaccorso@21:1/5 to All on Wed Jun 11 20:40:01 2025
    Source: konsole
    Version: 4:25.04.0-1
    Severity: grave
    Tags: security upstream
    Justification: user security hole
    X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
    Control: close -1 4:25.04.0-2
    Control: found -1 4:22.12.3-1

    Hi,

    The following vulnerability was published for konsole.

    CVE-2025-49091[0]:
    | KDE Konsole before 25.04.2 allows remote code execution in a certain
    | scenario. It supports loading URLs from the scheme handlers such as
    | a ssh:// or telnet:// or rlogin:// URL. This can be executed
    | regardless of whether the ssh, telnet, or rlogin binary is
    | available. In this mode, there is a code path where if that binary
    | is not available, Konsole falls back to using /bin/bash for the
    | given arguments (i.e., the URL) provided. This allows an attacker to
    | execute arbitrary code.


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-49091
    https://www.cve.org/CVERecord?id=CVE-2025-49091
    [1] https://www.openwall.com/lists/oss-security/2025/06/10/5
    [2] https://kde.org/info/security/advisory-20250609-1.txt
    [3] https://invent.kde.org/utilities/konsole/-/commit/09d20dea109050b4c02fb73095f327b5642a2b75

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Fred Blogs
      Mon Sep 15 00:03:12 2025
      from Uk via SSH
    • Plume
      Sun Sep 14 09:34:52 2025
      from Uk via Raw
    • Gretchiie
      Sun Sep 14 06:07:30 2025
      from Derry, Nh via Telnet
    • Thlc
      Sat Sep 13 17:11:34 2025
      from Rognac, France via Telnet
    • Thlc
      Sat Sep 13 17:04:03 2025
      from Rognac, France via Telnet
    • Thlc
      Sat Sep 13 16:32:19 2025
      from Rognac, France via SSH
    • Thlc
      Sat Sep 13 15:41:11 2025
      from Rognac, France via SSH
    • Thlc
      Sat Sep 13 07:56:03 2025
      from Rognac, France via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 546
    Nodes: 16 (2 / 14)
    Uptime: 05:10:21
    Calls: 10,386
    Calls today: 1
    Files: 14,058
    Messages: 6,416,629

© >>> Magnum BBS <<<, 2025