Lucene search

K
ubuntuUbuntuUSN-1114-1
HistoryApr 18, 2011 - 12:00 a.m.

KDENetwork vulnerability

2011-04-1800:00:00
ubuntu.com
39

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.005

Percentile

76.3%

Releases

  • Ubuntu 10.10
  • Ubuntu 10.04
  • Ubuntu 9.10

Packages

  • kdenetwork - networking applications for KDE 4

Details

It was discovered that KGet did not properly perform input validation when
processing metalink files. If a user were tricked into opening a crafted
metalink file, a remote attacker could overwrite files via directory
traversal, which could eventually lead to arbitrary code execution.

OSVersionArchitecturePackageVersionFilename
Ubuntu9.10noarchkget< 4:4.3.2-0ubuntu4.5UNKNOWN
Ubuntu9.10noarchkde-zeroconf< 4:4.3.2-0ubuntu4.5UNKNOWN
Ubuntu9.10noarchkdenetwork-dbg< 4:4.3.2-0ubuntu4.5UNKNOWN
Ubuntu9.10noarchkdenetwork-filesharing< 4:4.3.2-0ubuntu4.5UNKNOWN
Ubuntu9.10noarchkopete< 4:4.3.2-0ubuntu4.5UNKNOWN
Ubuntu9.10noarchkppp< 4:4.3.2-0ubuntu4.5UNKNOWN
Ubuntu9.10noarchkrdc< 4:4.3.2-0ubuntu4.5UNKNOWN
Ubuntu9.10noarchkrfb< 4:4.3.2-0ubuntu4.5UNKNOWN
Ubuntu9.10noarchlibkopete-dev< 4:4.3.2-0ubuntu4.5UNKNOWN
Ubuntu9.10noarchlibkopete4< 4:4.3.2-0ubuntu4.5UNKNOWN
Rows per page:
1-10 of 311

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.005

Percentile

76.3%