PT-2014-1879 · Kde · Kdelibs

Publicado

2014-06-29

·

Atualizado

2024-06-15

·

CVE-2014-3494

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions kdelibs versions 4.10.95 through 4.12.5
Description The issue concerns the POP3 kioslave in kdelibs, where it fails to properly generate warning notifications, allowing man-in-the-middle attackers to obtain sensitive information via an invalid certificate. Multiple vulnerabilities in the kdelibs package can lead to a breach of protected information, and exploitation can be carried out remotely.
Recommendations For kdelibs versions 4.10.95 through 4.12.5, update to version 4.13.3 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Exploit

Correção

RCE

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09700
CVE-2014-3494
MGASA-2014-0432
OPENSUSE-SU-2024:10011-1

Produtos afetados

Kdelibs