CVE-2018-19120

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-19120
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-19120.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-19120
Related
Published
2018-11-29T21:29:00Z
Modified
2024-11-21T03:57:21Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.

References

Affected packages

Debian:11 / kio-extras

Package

Name
kio-extras
Purl
pkg:deb/debian/kio-extras?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:18.08.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / kio-extras

Package

Name
kio-extras
Purl
pkg:deb/debian/kio-extras?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:18.08.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / kio-extras

Package

Name
kio-extras
Purl
pkg:deb/debian/kio-extras?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:18.08.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}