CVE-2022-23853
Summary
| CVE | CVE-2022-23853 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-11 18:15:00 UTC |
| Updated | 2024-01-15 17:15:00 UTC |
| Description | The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened (due to a misunderstanding of the QProcess API, that was never intended). This can be an untrusted directory. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Kde |
Kate |
All |
All |
All |
All |
| Application |
Kde |
Ktexteditor |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| KTextEditor: Arbitrary Local Code Execution (GLSA 202401-21) — Gentoo security |
|
security.gentoo.org |
|
| kde.org/info/security/advisory-20220131-1.txt |
CONFIRM |
kde.org |
|
| Kate - KDE Applications |
MISC |
apps.kde.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182893 Debian Security Update for ktexteditorkate (CVE-2022-23853)
- 282348 Fedora Security Update for kate (FEDORA-2022-74707ed2dd)
- 710838 Gentoo Linux KTextEditor Arbitrary Local Code Execution Vulnerability (GLSA 202401-21)
- 751878 SUSE Enterprise Linux Security Update for libqt5-qtbase (SUSE-SU-2022:0841-1)
- 751891 OpenSUSE Security Update for libqt5-qtbase (openSUSE-SU-2022:0841-1)