CVE-2010-1511

NameCVE-2010-1511
DescriptionKGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kdenetworksourcelenny(not affected)
kdenetworksource(unstable)4:4.4.4-1low

Notes

[lenny] - kdenetwork <not-affected> (Metalink plugin not yet present)
http://seclists.org/fulldisclosure/2010/May/164

Search for package or bug name: Reporting problems