Debian 10512 Published by

Debian GNU/Linux has received two Konsole security updates for Debian 10 (Buster) Extended LTS and 11 (Bullseye) LTS:

ELA-1466-1 konsole security update
[DSA 5945-1] konsole security update



[SECURITY] [DSA 5945-1] konsole security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5945-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
June 20, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : konsole
CVE ID : CVE-2025-49091

Dennis Dast discovered that the Konsole terminal emulator insecurely
handled the telnet URI scheme, which could result in the execution
of arbitrary code in some configurations.

For the stable distribution (bookworm), this problem has been fixed in
version 4:22.12.3-1+deb12u1.

We recommend that you upgrade your konsole packages.

For the detailed security status of konsole please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/konsole

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


ELA-1466-1 konsole security update


Package : konsole
Version : 4:18.04.0-1+deb10u1 (buster)

Related CVEs :
CVE-2025-49091

It was discovered that there was a potential remote code execution
vulnerability in konsole, the X terminal emulator of the KDE desktop
environment.


ELA-1466-1 konsole security update