Lucene search

K
cve[email protected]CVE-2010-1511
HistoryMay 17, 2010 - 9:00 p.m.

CVE-2010-1511

2010-05-1721:00:01
CWE-264
web.nvd.nist.gov
37
cve-2010-1511
kget
kde sc
download confirmation
remote attackers
file overwrite
metalink file

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

9.2 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

82.1%

KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.

Affected configurations

NVD
Node
kdekgetMatch2.4.2
AND
kdekde_scMatch2.2.0
OR
kdekde_scMatch3.5.10
OR
kdekde_scMatch4.0.0
OR
kdekde_scMatch4.0.0alpha1
OR
kdekde_scMatch4.0.0alpha2
OR
kdekde_scMatch4.0.0beta1
OR
kdekde_scMatch4.0.0beta2
OR
kdekde_scMatch4.0.0beta3
OR
kdekde_scMatch4.0.0beta4
OR
kdekde_scMatch4.0.0rc1
OR
kdekde_scMatch4.0.0rc2
OR
kdekde_scMatch4.0.1
OR
kdekde_scMatch4.0.2
OR
kdekde_scMatch4.0.3
OR
kdekde_scMatch4.0.4
OR
kdekde_scMatch4.0.5
OR
kdekde_scMatch4.1.0
OR
kdekde_scMatch4.1.0alpha1
OR
kdekde_scMatch4.1.0beta1
OR
kdekde_scMatch4.1.0beta2
OR
kdekde_scMatch4.1.0rc
OR
kdekde_scMatch4.1.1
OR
kdekde_scMatch4.1.2
OR
kdekde_scMatch4.1.3
OR
kdekde_scMatch4.1.4
OR
kdekde_scMatch4.1.80
OR
kdekde_scMatch4.1.85
OR
kdekde_scMatch4.1.96
OR
kdekde_scMatch4.2beta2
OR
kdekde_scMatch4.2rc
OR
kdekde_scMatch4.2.0
OR
kdekde_scMatch4.2.1
OR
kdekde_scMatch4.2.2
OR
kdekde_scMatch4.2.3
OR
kdekde_scMatch4.2.4
OR
kdekde_scMatch4.3.0
OR
kdekde_scMatch4.3.0beta1
OR
kdekde_scMatch4.3.0beta3
OR
kdekde_scMatch4.3.0rc1
OR
kdekde_scMatch4.3.0rc2
OR
kdekde_scMatch4.3.0rc3
OR
kdekde_scMatch4.3.1
OR
kdekde_scMatch4.3.2
OR
kdekde_scMatch4.3.3
OR
kdekde_scMatch4.3.4
OR
kdekde_scMatch4.3.5
OR
kdekde_scMatch4.4.0
OR
kdekde_scMatch4.4.0beta1
OR
kdekde_scMatch4.4.0beta2
OR
kdekde_scMatch4.4.0rc1
OR
kdekde_scMatch4.4.0rc2
OR
kdekde_scMatch4.4.0rc3
OR
kdekde_scMatch4.4.1
OR
kdekde_scMatch4.4.2
OR
kdekde_scMatch4.4.3

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

9.2 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

82.1%