Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-6410

Опубликовано: 28 фев. 2017
Источник: redhat
CVSS3: 5.3

Описание

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kdelibsWill not fix
Red Hat Enterprise Linux 6kdelibsWill not fix
Red Hat Enterprise Linux 7kdelibsWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1427808kdelibs: Information Leak when accessing https when using a malicious PAC file

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

CVSS3: 5.5
nvd
почти 9 лет назад

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

CVSS3: 5.5
debian
почти 9 лет назад

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 call ...

CVSS3: 5.5
github
больше 3 лет назад

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

5.3 Medium

CVSS3