CVE-2011-1586

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
27/04/2011
Last modified:
11/04/2025

Description

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kde:kde_sc:*:*:*:*:*:*:*:* 4.6.2 (including)
cpe:2.3:a:kde:kde_sc:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:3.5.10:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.0.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools