It's 2018 and You Can Still p0wn Your Linux Box by Plugging in a USB Stick

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Linux users running KDE Plasma desktop environments need to apply patches to fix a bug that can lead to malicious code execution every time a user mounts a USB thumb drive on his computer.

The KDE Plasma team has released versions 5.8.9 and 5.12.0 to address the issue, tracked as CVE-2018-6791 and categorized as an "arbitrary command execution" vulnerability
According to a description of the bug, USB thumb drives that contain the characters `` or $() in the volume label will execute the text contained within these characters as shell commands.
This means that an attacker can place malicious code in a USB thumb drive's name and have it automatically execute on a victim's computer when the victim mounts the USB via KDE to view its contents.
The only condition is that the victim must run a KDE desktop environment and that the USB thumb drive must be VFAT formatted.
For example, inserting a VFAT USB thumb drive with the volume label $(touch b) or `touch b` will create a file named "b" in the user's home directory.
The bug has been described "hilarious" by most security researchers because such issues have been fixed in the late 90s and early 2000s by applying proper input sanitization techniques.

All KDE Plasma versions before v5.12.0 are considered vulnerable. Users who cannot update are advised to mount new USB devices via other methods instead of the KDE Device Notifier app (handles pluggable devices for KDE environment).
 
D

Deleted member 65228

Linux users running KDE Plasma desktop environments need to apply patches to fix a bug that can lead to malicious code execution every time a user mounts a USB thumb drive on his computer.
Looks like females are in the clear, ball out with inserting the USB drives! :LOL:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top