|
|
Log in / Subscribe / Register

kdenetwork: arbitrary code execution

Package(s):kdenetwork CVE #(s):CVE-2011-1586
Created:April 19, 2011 Updated:May 2, 2011
Description: From the Ubuntu advisory:

It was discovered that KGet did not properly perform input validation when processing metalink files. If a user were tricked into opening a crafted metalink file, a remote attacker could overwrite files via directory traversal, which could eventually lead to arbitrary code execution.

Alerts:
Ubuntu USN-1114-1 kdenetwork 2011-04-18
Red Hat RHSA-2011:0465-01 kdenetwork 2011-04-21
Mandriva MDVSA-2011:081 kdenetwork4 2011-05-02

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds