CVE-2010-1000

KDE SC 4.0.0-4.4.3 - Unauthenticated Arbitrary File Write via Metalink File Element

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

References (21)

Core 21
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/40141
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-938-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/1101
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42423
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/511294/100/0/threaded
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1144
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:098
Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2010-69/
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/58628
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/511281/100/0/threaded
Vendor Advisory x_refsource_confirm
http://www.kde.org/info/security/advisory-20100513-1.txt
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3096
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051692.html
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=oss-security&m=127378789518426&w=2
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39528
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1142
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058580.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023984
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/64690
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39787

Scores

EPSS 0.0237
EPSS Percentile 85.2%

Details

CWE
CWE-22
Status published
Products (27)
kde/kde_sc 4.0.0 (9 CPE variants)
kde/kde_sc 4.0.1
kde/kde_sc 4.0.2
kde/kde_sc 4.0.3
kde/kde_sc 4.0.4
kde/kde_sc 4.0.5
kde/kde_sc 4.1.0 (5 CPE variants)
kde/kde_sc 4.1.1
kde/kde_sc 4.1.2
kde/kde_sc 4.1.3
... and 17 more
Published May 17, 2010
Tracked Since Feb 18, 2026