Comment 26 for bug 578856

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package kdenetwork - 4:4.4.2-0ubuntu4.1

---------------
kdenetwork (4:4.4.2-0ubuntu4.1) lucid-security; urgency=low

  * SECURITY UPDATE: file name directory traversal attack (LP: #578856).
   - Add debian/patches/kubuntu_01_kget_CVE-2010-1000.diff
   - kget/ui/metalinkcreator/metalinker.cpp check filename is valid
   - kget/transfer-plugins/metalink/metalink.cpp if the dialog was not accepted untick every file, so that the download does not start
   - CVE-2010-1000, SA39528
 -- Jonathan Riddell <email address hidden> Tue, 11 May 2010 16:26:45 +0100