CVE-2013-2074
kde4libs - security update
EPSS 2.0%
描述
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.
如何修補 CVE-2013-2074
要修補 CVE-2013-2074,請將受影響套件升級到下列已修補版本。
- Debian/kde4libs—升級至 4:4.10.5-1 或更新版本
- Debian/kde4libs—升級至 4:4.8.4-4+deb7u3 或更新版本
CVE-2013-2074 正在被利用嗎?
低 — EPSS 為 2.0%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 4:4.10.5-1
- from 0, < 4:4.8.4-4+deb7u3