5.8
CVSSv2

CVE-2010-1000

Published: 17/05/2010 Updated: 10/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in KGet in KDE SC 4.0.0 up to and including 4.4.3 allows remote malicious users to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde sc 4.3.0

kde kde sc 4.4.0

kde kde sc 4.1.80

kde kde sc 4.1.85

kde kde sc 4.1.1

kde kde sc 4.2.2

kde kde sc 4.0.0

kde kde sc 4.0.4

kde kde sc 4.0.5

kde kde sc 4.3.4

kde kde sc 4.3.5

kde kde sc 4.4.2

kde kde sc 4.4.3

kde kde sc 4.1.3

kde kde sc 4.1.2

kde kde sc 4.0.2

kde kde sc 4.0.3

kde kde sc 4.1.0

kde kde sc 4.2.4

kde kde sc 4.3.2

kde kde sc 4.3.3

kde kde sc 4.4.1

kde kde sc 4.2

kde kde sc 4.1.4

kde kde sc 4.2.1

kde kde sc 4.0.1

kde kde sc 4.3.1

kde kde sc 4.1.96

kde kde sc 4.2.3

kde kde sc 4.2.0

Vendor Advisories

It was discovered that KGet did not properly perform input validation when processing metalink files If a user were tricked into opening a crafted metalink file, a remote attacker could overwrite files via directory traversal, which could eventually lead to arbitrary code execution (CVE-2010-1000) ...