VulnerabilityModified
CVE-2010-1511
KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.
MEDIUM 6.4EPSS 3.32%
Does this matter?
Lower severity and a low EPSS score (3.32%). Track it; it rarely justifies an emergency change on its own.
Description
KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 3.32% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- kde/kget · kde/kde sc
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051692.html
- http://marc.info/?l=oss-security&m=127378789518426&w=2
- http://osvdb.org/64689
- http://secunia.com/advisories/39528Vendor Advisory
- http://secunia.com/advisories/39787Vendor Advisory
- http://secunia.com/secunia_research/2010-70/Vendor Advisory
- http://securitytracker.com/id?1023984
- http://www.kde.org/info/security/advisory-20100513-1.txtVendor Advisory
- http://www.securityfocus.com/archive/1/511279/100/0/threaded
- http://www.securityfocus.com/archive/1/511294/100/0/threaded
- http://www.securityfocus.com/bid/40141
- http://www.ubuntu.com/usn/USN-938-1
- http://www.vupen.com/english/advisories/2010/1142Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1144Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3096Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58629
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051692.html
- http://marc.info/?l=oss-security&m=127378789518426&w=2
- http://osvdb.org/64689
- http://secunia.com/advisories/39528Vendor Advisory
- http://secunia.com/advisories/39787Vendor Advisory
- http://secunia.com/secunia_research/2010-70/Vendor Advisory
- http://securitytracker.com/id?1023984
- http://www.kde.org/info/security/advisory-20100513-1.txtVendor Advisory
- http://www.securityfocus.com/archive/1/511279/100/0/threaded
- http://www.securityfocus.com/archive/1/511294/100/0/threaded
- http://www.securityfocus.com/bid/40141
- http://www.ubuntu.com/usn/USN-938-1
- http://www.vupen.com/english/advisories/2010/1142Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1144Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.