CVE Vulnerabilities

CVE-2010-1511

Published: May 17, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
7.5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.

Affected Software

Name Vendor Start Version End Version
Kget Kde 2.4.2 (including) 2.4.2 (including)
Kdenetwork Ubuntu dapper *
Kdenetwork Ubuntu hardy *
Kdenetwork Ubuntu lucid *

References