KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2010-05-17 14:00
Updated : 2018-10-10 12:57
NVD link : CVE-2010-1511
Mitre link : CVE-2010-1511
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
kde
- kde_sc
- kget