Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2010-1511 - CERT CVE
CVE-2010-1511
ID
CVE-2010-1511
Sažetak
KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.
Reference
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051692.html
http://marc.info/?l=oss-security&m=127378789518426&w=2
http://osvdb.org/64689
http://secunia.com/advisories/39528
http://secunia.com/advisories/39787
http://secunia.com/secunia_research/2010-70/
http://securitytracker.com/id?1023984
http://www.kde.org/info/security/advisory-20100513-1.txt
http://www.securityfocus.com/archive/1/511279/100/0/threaded
http://www.securityfocus.com/archive/1/511294/100/0/threaded
http://www.securityfocus.com/bid/40141
http://www.ubuntu.com/usn/USN-938-1
http://www.vupen.com/english/advisories/2010/1142
http://www.vupen.com/english/advisories/2010/1144
http://www.vupen.com/english/advisories/2010/3096
https://exchange.xforce.ibmcloud.com/vulnerabilities/58629
CVSS
Base:
6.4
Impact:
4.9
Exploitability:
10.0
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
NONE
PARTIAL
PARTIAL
CVSS vektor
AV:N/AC:L/Au:N/C:N/I:P/A:P
Zadnje važnije ažuriranje
10-10-2018 - 19:57
Objavljeno
17-05-2010 - 21:00