Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1586

Опубликовано: 11 апр. 2011
Источник: redhat
CVSS2: 7.5

Описание

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

Дополнительная информация

Статус:

Important
Дефект:
CWE-73->CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=697042kdenetwork: incomplete fix for CVE-2010-1000

7.5 High

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

nvd
почти 15 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

debian
почти 15 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNa ...

github
больше 3 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

oracle-oval
почти 15 лет назад

ELSA-2011-0465: kdenetwork security update (IMPORTANT)

7.5 High

CVSS2