USN-1114-1: KDENetwork vulnerability
18 April 2011
An attacker could overwrite files owned by the user if KGet opened a crafted metalink file.
- kdenetwork - networking applications for KDE 4
It was discovered that KGet did not properly perform input validation when
processing metalink files. If a user were tricked into opening a crafted
metalink file, a remote attacker could overwrite files via directory
traversal, which could eventually lead to arbitrary code execution.
The problem can be corrected by updating your system to the following package versions:
After a standard system update you need to restart KGet to make all the