First published: Mon Dec 08 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) trash, (3) tar, (4) thumbnail, (5) smtps, (6) smtp, (7) smb, (8) remote, (9) recentdocuments, (10) nntps, (11) nntp, (12) network, (13) mbox, (14) ldaps, (15) ldap, (16) fonts, (17) file, (18) desktop, (19) cgi, (20) bookmarks, or (21) ar scheme, which is not properly handled in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kwebkitpart | <=1.3.3 | |
Red Hat KDE Runtime | <=4.14.2 | |
KDE kio | <=5.1.1 | |
openSUSE | =13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8600 has a high severity due to the potential for remote attackers to exploit multiple cross-site scripting vulnerabilities.
To fix CVE-2014-8600, update KDE-Runtime to version 4.14.3 or later, kwebkitpart to version 1.3.4 or later, and kio-extras to version 5.1.2 or later.
CVE-2014-8600 affects KDE-Runtime 4.14.2 and earlier, kwebkitpart 1.3.3 and earlier, and kio-extras 5.1.1 and earlier.
Yes, CVE-2014-8600 can potentially lead to data theft as it allows attackers to inject arbitrary web scripts into the affected applications.
Exploiting CVE-2014-8600 can result in unauthorized actions being performed on behalf of the user, session hijacking, or redirection to malicious sites.