KDE Frameworks 5.61 release with security fix

Published platform release KDE Framework 5.61.0, which provides a restructured and ported to Qt 5 core set of libraries and runtime components that underlie KDE. The framework includes more 70 libraries, some of which can work as self-contained add-ons on top of Qt, and some form the KDE software stack.

The new release fixes a vulnerability that ΡΠΎΠΎΠ±Ρ‰Π°Π»ΠΎΡΡŒ a few days ago, allowing arbitrary shell commands to be executed when a user browses a directory or archive containing specially crafted ".desktop" and ".directory" files. In the new release of the kconfig libraries included with KDE Frameworks 5.61, when parsing ".desktop" and ".directory" files terminated support for expanding Shell blocks "$(...)" in directives with the "[$e]" marker, such as "Icon[$e]" (in the "Exec" directive, support for shell expansion is retained). Among other changes, the provision of the use of a set of protocols and extensions in KWayland wayland-protocols, which complement the capabilities of the basic Wayland protocol.

Source: opennet.ru

Add a comment