First published: Tue Nov 13 2018(Updated: )
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kde Kde Applications | <18.12.0 | |
redhat/kio-extras | <18.12.0 | 18.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19120 is a vulnerability in the HTML thumbnailer plugin in KDE Applications before 18.12.0 that allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
CVE-2018-19120 has a severity level of 7.5 (high).
CVE-2018-19120 affects systems running KDE Applications before version 18.12.0, specifically the HTML thumbnailer plugin, and allows attackers to trigger outbound TCP connections to arbitrary IP addresses, revealing the source IP address.
To fix CVE-2018-19120, update your KDE Applications to version 18.12.0 or higher.
More information about CVE-2018-19120 can be found in the following references: [1] [2] [3].