kdenetwork: arbitrary code execution
| Package(s): | kdenetwork | CVE #(s): | CVE-2011-1586 | ||||||||||||
| Created: | April 19, 2011 | Updated: | May 2, 2011 | ||||||||||||
| Description: | From the Ubuntu advisory:
It was discovered that KGet did not properly perform input validation when processing metalink files. If a user were tricked into opening a crafted metalink file, a remote attacker could overwrite files via directory traversal, which could eventually lead to arbitrary code execution. | ||||||||||||||
| Alerts: |
| ||||||||||||||
