CVE-2017-6410

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kde:kdelibs:*:*:*:*:*:*:*:*
cpe:2.3:a:kde:kio:*:*:*:*:*:*:*:*

Information

Published : 2017-03-01 22:59

Updated : 2019-10-02 17:03


NVD link : CVE-2017-6410

Mitre link : CVE-2017-6410


JSON object : View

CWE
CWE-319

Cleartext Transmission of Sensitive Information

Advertisement

dedicated server usa

Products Affected

kde

  • kio
  • kdelibs