KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kget | Kde | 2.4.2 (including) | 2.4.2 (including) |
Kdenetwork | Ubuntu | dapper | * |
Kdenetwork | Ubuntu | hardy | * |
Kdenetwork | Ubuntu | lucid | * |