Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) trash, (3) tar, (4) thumbnail, (5) smtps, (6) smtp, (7) smb, (8) remote, (9) recentdocuments, (10) nntps, (11) nntp, (12) network, (13) mbox, (14) ldaps, (15) ldap, (16) fonts, (17) file, (18) desktop, (19) cgi, (20) bookmarks, or (21) ar scheme, which is not properly handled in an error message.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://ubuntu.com/usn/usn-2414-1 | patch vendor advisory |
http://lists.opensuse.org/opensuse-updates/2015-03/msg00068.html | vendor advisory |
http://seclists.org/fulldisclosure/2014/Nov/54 | exploit mailing list |
http://www.securityfocus.com/bid/71190 | vdb entry |
https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-8600/ | exploit |