CVE-2018-6790
07.02.2018, 02:29
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kde | plasma-workspace | 𝑥 < 5.12.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| kcm |
| ||
| kde-settings |
| ||
| kde-settings-ksplash |
| ||
| kde-settings-minimal |
| ||
| kde-settings-plasma |
| ||
| kde-settings-pulseaudio |
| ||
| kde-style-oxygen |
| ||
| kde-workspace |
| ||
| kde-workspace-devel |
| ||
| kde-workspace-ksplash-themes |
| ||
| kde-workspace-libs |
| ||
| kdeclassic-cursor-theme |
| ||
| kdelibs |
| ||
| kdelibs-apidocs |
| ||
| kdelibs-common |
| ||
| kdelibs-devel |
| ||
| kdelibs-ktexteditor |
| ||
| kgreeter-plugins |
| ||
| khotkeys |
| ||
| khotkeys-libs |
| ||
| kinfocenter |
| ||
| kmag |
| ||
| kmenuedit |
| ||
| ksysguard |
| ||
| ksysguard-libs |
| ||
| ksysguardd |
| ||
| kwin |
| ||
| kwin-gles |
| ||
| kwin-gles-libs |
| ||
| kwin-libs |
| ||
| libkworkspace |
| ||
| oxygen-cursor-themes |
| ||
| plasma-scriptengine-python |
| ||
| plasma-scriptengine-ruby |
| ||
| qt-settings |
| ||
| virtuoso-opensource |
| ||
| virtuoso-opensource-utils |
|
Common Weakness Enumeration
References