MGASA-2018-0477
Dashboard / Vulnerabilities / MGASA-2018-0477
Summary: Updated kio-extras packages fix security vulnerability
Details: The HTML thumbnailer was incorrectly accessing some content of remote URLs listed in HTML files. This meant that the owners of the servers referred in HTML files in your system could have seen in their access logs your IP address every time the thumbnailer tried to create the thumbnail (CVE-2018-19120).
References: https://advisories.mageia.org/MGASA-2018-0477.html, https://bugs.mageia.org/show_bug.cgi?id=23868, https://www.kde.org/info/security/advisory-20181012-1.txt, https://lists.fedoraproject.org/archives/list/[email protected]/thread/CWRCGXLPJHM4OFD66BINH2FIMYHRCRKF/
Affected packages
Package
Name: kio-extras
Purl: pkg:rpm/mageia/kio-extras?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
