Lucene search

K
redhatRedHatRHSA-2011:0465
HistoryApr 21, 2011 - 12:00 a.m.

(RHSA-2011:0465) Important: kdenetwork security update

2011-04-2100:00:00
access.redhat.com
18

EPSS

0.005

Percentile

76.3%

The kdenetwork packages contain networking applications for the K Desktop
Environment (KDE).

A directory traversal flaw was found in the way KGet, a download manager,
handled the “file” element in Metalink files. An attacker could use this
flaw to create a specially-crafted Metalink file that, when opened, would
cause KGet to overwrite arbitrary files accessible to the user running
KGet. (CVE-2011-1586)

Users of kdenetwork should upgrade to these updated packages, which contain
a backported patch to resolve this issue. The desktop must be restarted
(log out, then log back in) for this update to take effect.