Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1586

Опубликовано: 11 апр. 2011
Источник: redhat
CVSS2: 7.5
EPSS Низкий

Описание

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

Дополнительная информация

Статус:

Important
Дефект:
CWE-73->CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=697042kdenetwork: incomplete fix for CVE-2010-1000

EPSS

Процентиль: 74%
0.00847
Низкий

7.5 High

CVSS2

Связанные уязвимости

ubuntu
около 14 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

nvd
около 14 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

debian
около 14 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNa ...

github
около 3 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

oracle-oval
около 14 лет назад

ELSA-2011-0465: kdenetwork security update (IMPORTANT)

EPSS

Процентиль: 74%
0.00847
Низкий

7.5 High

CVSS2