kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
{ "binaries": [ { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "kdelibs-bin" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "kdelibs5-data" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "kdelibs5-dev" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "kdelibs5-plugins" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "kdoctools" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkcmutils4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkde3support4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkdeclarative5" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkdecore5" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkdesu5" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkdeui5" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkdewebkit5" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkdnssd4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkemoticons4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkfile4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkhtml5" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkidletime4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkimproxy4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkio5" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkjsapi4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkjsembed4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkmediaplayer4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libknewstuff2-4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libknewstuff3-4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libknotifyconfig4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkntlm4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkparts4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkprintutils4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkpty4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkrosscore4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkrossui4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libktexteditor4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkunitconversion4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libkutils4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libnepomuk4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libnepomukquery4a" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libnepomukutils4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libplasma3" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libsolid4" }, { "binary_version": "4:4.13.3-0ubuntu0.4", "binary_name": "libthreadweaver4" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "kdelibs-bin" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "kdelibs5-data" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "kdelibs5-dev" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "kdelibs5-plugins" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "kdoctools" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkcmutils4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkde3support4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkdeclarative5" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkdecore5" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkdesu5" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkdeui5" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkdewebkit5" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkdnssd4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkemoticons4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkfile4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkhtml5" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkidletime4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkimproxy4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkio5" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkjsapi4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkjsembed4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkmediaplayer4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libknewstuff2-4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libknewstuff3-4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libknotifyconfig4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkntlm4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkparts4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkprintutils4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkpty4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkrosscore4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkrossui4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libktexteditor4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkunitconversion4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libkutils4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libplasma3" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libsolid4" }, { "binary_version": "4:4.14.16-0ubuntu3.1", "binary_name": "libthreadweaver4" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "5.18.0-0ubuntu1.1", "binary_name": "kio" }, { "binary_version": "5.18.0-0ubuntu1.1", "binary_name": "kio-dev" }, { "binary_version": "5.18.0-0ubuntu1.1", "binary_name": "libkf5kiocore5" }, { "binary_version": "5.18.0-0ubuntu1.1", "binary_name": "libkf5kiofilewidgets5" }, { "binary_version": "5.18.0-0ubuntu1.1", "binary_name": "libkf5kiontlm5" }, { "binary_version": "5.18.0-0ubuntu1.1", "binary_name": "libkf5kiowidgets5" } ], "availability": "No subscription required" }