PT-2014-1878 · Kde · Kdelibs
Vincent Danen
·
Published
2014-02-05
·
Updated
2014-06-29
·
CVE-2013-2074
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
kdelibs versions 4.10.3 and earlier
kdelibs versions prior to 4.12.5-r1
Description
The issue allows attackers to discover credentials via a crafted request that triggers an internal server error, which includes the username and password in an error message. Multiple vulnerabilities in the kdelibs package can lead to a breach of protected information, and exploitation can be carried out remotely.
Recommendations
For kdelibs versions 4.10.3 and earlier, update to a version later than 4.10.3.
For kdelibs versions prior to 4.12.5-r1, update to version 4.12.5-r1 or later.
Fix
RCE
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kdelibs