CVE-2013-2074

Publication date 15 May 2013

Last updated 24 July 2024


Ubuntu priority

kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.

Status

Package Ubuntu Release Status
kde4libs 13.04 raring
Fixed 4:4.10.2-0ubuntu2.2
12.10 quantal
Fixed 4:4.9.5-0ubuntu0.2
12.04 LTS precise
Fixed 4:4.8.5-0ubuntu0.2
10.04 LTS lucid Ignored end of life

References

Related Ubuntu Security Notices (USN)

Other references