Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1586

Опубликовано: 27 апр. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8

Описание

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

РелизСтатусПримечание
dapper

ignored

end of life
devel

released

4:4.6.2-0ubuntu3
hardy

ignored

end of life
karmic

released

4:4.3.2-0ubuntu4.5
lucid

released

4:4.4.5-0ubuntu1.1
maverick

released

4:4.5.1-0ubuntu2.2
upstream

needs-triage

Показывать по

EPSS

Процентиль: 74%
0.00847
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

redhat
около 14 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

nvd
около 14 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

debian
около 14 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNa ...

github
около 3 лет назад

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

oracle-oval
около 14 лет назад

ELSA-2011-0465: kdenetwork security update (IMPORTANT)

EPSS

Процентиль: 74%
0.00847
Низкий

5.8 Medium

CVSS2