PT-2014-1878 · Kde · Kdelibs

Vincent Danen

·

Published

2014-02-05

·

Updated

2014-06-29

·

CVE-2013-2074

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions kdelibs versions 4.10.3 and earlier kdelibs versions prior to 4.12.5-r1
Description The issue allows attackers to discover credentials via a crafted request that triggers an internal server error, which includes the username and password in an error message. Multiple vulnerabilities in the kdelibs package can lead to a breach of protected information, and exploitation can be carried out remotely.
Recommendations For kdelibs versions 4.10.3 and earlier, update to a version later than 4.10.3. For kdelibs versions prior to 4.12.5-r1, update to version 4.12.5-r1 or later.

Fix

RCE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09700
CVE-2013-2074
DLA-952-1
OPENSUSE-SU-2024:10394-1

Affected Products

Kdelibs