Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-6410

Опубликовано: 28 фев. 2017
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kdelibsWill not fix
Red Hat Enterprise Linux 6kdelibsWill not fix
Red Hat Enterprise Linux 7kdelibsWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1427808kdelibs: Information Leak when accessing https when using a malicious PAC file

EPSS

Процентиль: 55%
0.00828
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

CVSS3: 5.5
nvd
больше 9 лет назад

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

CVSS3: 5.5
debian
больше 9 лет назад

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 call ...

CVSS3: 5.5
github
больше 4 лет назад

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

EPSS

Процентиль: 55%
0.00828
Низкий

5.3 Medium

CVSS3