Multiple KDE Products CVE-2014-8600 Multiple Security Bypass Vulnerabilities
BID:71190
Info
Multiple KDE Products CVE-2014-8600 Multiple Security Bypass Vulnerabilities
| Bugtraq ID: | 71190 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8600 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2014 12:00AM |
| Updated: | May 07 2015 05:08PM |
| Credit: | T. Brown and D. Burton |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 |
| Not Vulnerable: | |
Discussion
Multiple KDE Products CVE-2014-8600 Multiple Security Bypass Vulnerabilities
Multiple KDE products are prone to multiple security-bypass vulnerabilities because they fail to sufficiently sanitize user-supplied input.
Successfully exploiting these issues will allow attackers to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
The following versions are vulnerable:
KDE kwebkitpart 1.3.4 and prior
KDE kde-runtime 4.14.3 and prior
KDE kio-extras 5.1.1 and prior
Multiple KDE products are prone to multiple security-bypass vulnerabilities because they fail to sufficiently sanitize user-supplied input.
Successfully exploiting these issues will allow attackers to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
The following versions are vulnerable:
KDE kwebkitpart 1.3.4 and prior
KDE kde-runtime 4.14.3 and prior
KDE kio-extras 5.1.1 and prior
Solution / Fix
Multiple KDE Products CVE-2014-8600 Multiple Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.