CVE-2011-1586

Priority
Description
Directory traversal vulnerability in the
KGetMetalink::File::isValidNameAttr function in
ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier
allows remote attackers to create arbitrary files via a .. (dot dot) in the
name attribute of a file element in a metalink file. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2010-1000.
Assigned-to
jdstrand
Notes
More Information

Updated: 2020-09-10 01:42:59 UTC (commit 81a23a978c4436cd99e1d040e9e73e9146876281)