Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.RC
  • Bug#1107672: konsole: CVE-2025-49091

    From Salvatore Bonaccorso@21:1/5 to All on Wed Jun 11 20:40:01 2025
    Source: konsole
    Version: 4:25.04.0-1
    Severity: grave
    Tags: security upstream
    Justification: user security hole
    X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
    Control: close -1 4:25.04.0-2
    Control: found -1 4:22.12.3-1

    Hi,

    The following vulnerability was published for konsole.

    CVE-2025-49091[0]:
    | KDE Konsole before 25.04.2 allows remote code execution in a certain
    | scenario. It supports loading URLs from the scheme handlers such as
    | a ssh:// or telnet:// or rlogin:// URL. This can be executed
    | regardless of whether the ssh, telnet, or rlogin binary is
    | available. In this mode, there is a code path where if that binary
    | is not available, Konsole falls back to using /bin/bash for the
    | given arguments (i.e., the URL) provided. This allows an attacker to
    | execute arbitrary code.


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-49091
    https://www.cve.org/CVERecord?id=CVE-2025-49091
    [1] https://www.openwall.com/lists/oss-security/2025/06/10/5
    [2] https://kde.org/info/security/advisory-20250609-1.txt
    [3] https://invent.kde.org/utilities/konsole/-/commit/09d20dea109050b4c02fb73095f327b5642a2b75

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
    • Gwylbert
      Fri Jun 5 06:28:52 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Thu Jun 4 23:42:23 2026
      from Berea, Ohio via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 149:42:02
    Calls: 12,091
    Calls today: 4
    Files: 15,000
    Messages: 6,517,583

© >>> Magnum BBS <<<, 2026