CVE-2013-2074
Published: 15 May 2013
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.
Priority
Status
Package | Release | Status |
---|---|---|
kde4libs Launchpad, Ubuntu, Debian |
lucid |
Ignored
(end of life)
|
precise |
Released
(4:4.8.5-0ubuntu0.2)
|
|
quantal |
Released
(4:4.9.5-0ubuntu0.2)
|
|
raring |
Released
(4:4.10.2-0ubuntu2.2)
|
|
upstream |
Needs triage
|
|
Patches: debdiff: https://bugs.launchpad.net/ubuntu/+source/kde4libs/+bug/1178286 other: https://projects.kde.org/projects/kde/kdelibs/repository/revisions/65d736dab592bced4410ccfa4699de89f78c96ca other: https://projects.kde.org/projects/kde/kdelibs/repository/revisions/898135a59d91184692ed1bcee8bb4c6d80d6f7b9 |