CVE-2010-1000
Publication date 12 May 2010
Last updated 24 July 2024
Ubuntu priority
Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.
Notes
jdstrand
overwrite of arbitrary files with permissions of user invoking the program. When combined with startup programs and sourced files can lead to arbitrary remote code execution.
References
Related Ubuntu Security Notices (USN)
- USN-938-1
- KDENetwork vulnerabilities
- 13 May 2010