7.2 High
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.6 High
AI Score
Confidence
High
0.007 Low
EPSS
Percentile
81.0%
Package : kde4libs
Version : 4:4.8.4-4+deb7u3
CVE ID : CVE-2013-2074 CVE-2017-6410 CVE-2017-8422
Debian Bug : 856890
Several vulnerabilities were discovered in kde4libs, the core libraries
for all KDE 4 applications. The Common Vulnerabilities and Exposures
project identifies the following problems:
CVE-2017-6410
Itzik Kotler, Yonatan Fridburg and Amit Klein of Safebreach Labs
reported that URLs are not sanitized before passing them to
FindProxyForURL, potentially allowing a remote attacker to obtain
sensitive information via a crafted PAC file.
CVE-2017-8422
Sebastian Krahmer from SUSE discovered that the KAuth framework
contains a logic flaw in which the service invoking dbus is not
properly checked. This flaw allows spoofing the identity of the
caller and gaining root privileges from an unprivileged account.
CVE-2013-2074
It was discovered that KIO would show web authentication
credentials in some error cases.
For Debian 7 "Wheezy", these problems have been fixed in version
4:4.8.4-4+deb7u3.
We recommend that you upgrade your kde4libs packages.
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 8 | powerpc | libnepomukutils4 | < 4:4.14.2-5+deb8u2 | libnepomukutils4_4:4.14.2-5+deb8u2_powerpc.deb |
Debian | 7 | all | kde4libs | < 4:4.8.4-4+deb7u3 | kde4libs_4:4.8.4-4+deb7u3_all.deb |
Debian | 8 | i386 | libkjsembed4 | < 4:4.14.2-5+deb8u2 | libkjsembed4_4:4.14.2-5+deb8u2_i386.deb |
Debian | 7 | armel | libkntlm4 | < 4:4.8.4-4+deb7u3 | libkntlm4_4:4.8.4-4+deb7u3_armel.deb |
Debian | 8 | kfreebsd-i386 | kdoctools | < 4:4.14.2-5+deb8u2 | kdoctools_4:4.14.2-5+deb8u2_kfreebsd-i386.deb |
Debian | 8 | amd64 | libkpty4 | < 4:4.14.2-5+deb8u2 | libkpty4_4:4.14.2-5+deb8u2_amd64.deb |
Debian | 8 | i386 | libkimproxy4 | < 4:4.14.2-5+deb8u2 | libkimproxy4_4:4.14.2-5+deb8u2_i386.deb |
Debian | 8 | kfreebsd-amd64 | libkdeclarative5 | < 4:4.14.2-5+deb8u2 | libkdeclarative5_4:4.14.2-5+deb8u2_kfreebsd-amd64.deb |
Debian | 7 | i386 | libkparts4 | < 4:4.8.4-4+deb7u3 | libkparts4_4:4.8.4-4+deb7u3_i386.deb |
Debian | 8 | kfreebsd-i386 | libkimproxy4 | < 4:4.14.2-5+deb8u2 | libkimproxy4_4:4.14.2-5+deb8u2_kfreebsd-i386.deb |
7.2 High
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.6 High
AI Score
Confidence
High
0.007 Low
EPSS
Percentile
81.0%